Breaking
Cyber CrimeDeveloping Story

Scammers Hijack University Emails for Fraud

Proofpoint says Nigerian scammers are using stolen .edu accounts to trick students with fake job offers and gift card schemes.

··1 hour ago·4 min read
Linkedin login screen with sign-in options
Photo by Zulfugar Karimov on Unsplash

Stolen university email accounts are being used to run fake job offers and gift card scams targeting students, according to security researchers at Proofpoint. The campaign, an advance fee fraud (AFF) scheme, tricks victims into depositing fake $1,000 checks and then sending the scammers gift cards purchased with their own money.

Proofpoint linked the operation to Nigeria after tricking the fraudsters into clicking on IP logging links. The researchers said they do not know how many people fell victim or how long the operation has been running.

How the scam begins

The scam starts with a phishing email sent to an .edu address. The message warns the recipient that their email account will be deactivated because of a made-up excuse such as retirement, graduation, or transfer. It then asks the victim to "verify" their address, which involves sharing their password.

Once the scammers have access to the account, they use it to send a second phishing email. This time, the message goes to students in the contacts list and to anyone else with an .edu address. The lure advertises a fake job for students to apply to.

Those who "get the job" are sent a copy of a check for $1,000 and told to deposit it. They are instructed to keep half as their salary and to purchase gift cards with the other half, which they should send back to the scammers.

The fake check and gift card trap

The checks are fake, and by the time the bank discovers the scam, the victim will have already purchased the gift cards and sent them away. The bank then reverses the deposit, leaving the victim $500 short.

Proofpoint researchers were "hired" for one of these jobs, which is how they uncovered the full modus operandi. They also found that if a victim doesn't follow through with the instructions, the scammers become aggressive. They suggest different payment services and even call the victim on the phone, pretending to be an FBI agent threatening legal action and arrest.

Why students are targeted

Proofpoint believes it knows why the scammers focus on college students. The researchers said that younger students may have less experience with email correspondence and are new to engaging with potential work or money-making opportunities.

"Younger students may have less experience with email correspondence and are new to engaging with potential work or money-making opportunities; alumni may still have active email accounts, but may not use them frequently, providing an opportunity for threat actors to hijack their contact lists; and staff and faculty are constantly receiving communications from students, parents, community members, etc. from a variety of personal and university emails," the experts said.

— Proofpoint researchers

The researchers also noted that by gaining access to a .edu account, threat actors can use the authority of the TLD to lend credibility to their scams both inside and outside of the target organization.

Attribution to Nigeria

Attributing the scam to any particular group is difficult, the researchers said. However, they managed to trick the fraudsters into using Grabify, an IP logging and URL shortening service usually used by online marketers.

The links are used to extract things like device information and IP addresses from whoever clicks them. Proofpoint's researchers found the engagement coming from Nigeria.

While there are ways to hide one's IP address, Proofpoint is rather confident about the location of this particular operation.

"While it is possible for threat actors to spoof their infrastructure, based on our investigations from hundreds of engagements, these AFF fraudsters typically use their real mobile network infrastructure to conduct their crimes. Even if the scammers do use a VPN, they often still click on researchers' links from their genuine devices due to the multi-platform communication style they use (and the desire to monetize, despite possible deanonymization)," Proofpoint concluded.

— Proofpoint researchers

What to do if you're targeted

Proofpoint's findings show that students should be cautious of unexpected emails asking them to verify their account details or share passwords. Any email that pressures you to act quickly or threatens account deactivation should be treated as suspicious.

If you receive a job offer that involves depositing a check and purchasing gift cards, it is a scam. Legitimate employers do not ask new hires to deposit checks and send money back. If you have already deposited a fake check and sent gift cards, contact your bank immediately.

The researchers did not detail specific steps universities should take. The source article did not include advice on reporting to the FBI's Internet Crime Complaint Center (IC3), multi-factor authentication, or monitoring login activity.

What we still don't know

Proofpoint said it does not know how many people fell victim or how long the operation has been going. The researchers also could not attribute the scam to a specific group. The investigation relied on IP logging after the fraudsters clicked on links set up by the researchers.

The source article did not include details on how universities should respond or whether any institutions have been notified.

Why this matters

The campaign shows how stolen .edu credentials can be repurposed for financial fraud. For students, the risk is not just a compromised email account but the potential loss of hundreds of dollars. For universities, the use of their domains as a trust signal in scams could erode confidence in official communications.

Businesses and consumers should treat unsolicited job offers and check-deposit schemes as red flags, regardless of the email address they appear to come from. The source article did not provide specific guidance for institutions, but the mechanics of the scam suggest that vigilance around email account security remains important.

#phishing#advance fee fraud#university email#proofpoint#gift card scam

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories