HackRead

Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent


Proofpoint uncovers hackers using compromised university accounts to send fake job offers, steal credentials, and run gift card scams, including FBI impersonation.

Cybercriminals are targeting university students with fake employment opportunities sent from compromised higher education email accounts. Research shared with Hackread.com by Proofpoint shows a multi-stage attack chain that starts with credential theft and can lead to account takeover (ATO) and advance-fee fraud (AFF).

Fake Account Warnings Steal University Credentials

The campaigns begin with emails warning students, staff, or alumni that their university account is due to be deactivated because of retirement, graduation, or transfer. Recipients are sent to credential-harvesting forms hosted on legitimate services including Google Forms, Microsoft Office, Wix, Jotform, and Zoho Forms.

To get around form restrictions on password collection, some pages avoided the word “password” and told victims to enter it under a field labelled “WORDWORD.” The forms also collect personally identifiable information (PII), including legal names, phone numbers, university email addresses, and personal email addresses.

Compromised Accounts Deliver Fake Job Offers

Once credentials are obtained, attackers use compromised university accounts to distribute fake job and internship offers. Proofpoint observed roles including remote personal assistants, secret shoppers, charity workers, and research assistants. The compromised accounts were used to send the offers both within the affected universities and to external recipients.

Example of a fraudulent remote personal assistant job offer used in the campaign. (Credit: Proofpoint)

According to Proofpoint’s report, its researchers engaged with the fraudsters to examine how they made money. After asking for a resume and checking whether the target had mobile banking and access to a printer, the scammers sent fraudulent checks averaging about $1,000. Victims were told to deposit the check, keep part as pay, and use the remainder to buy $100 gift cards before sending the codes back.

When researchers refused to send the money, the scammers escalated to repeated calls, text messages, and threats. In one case, a fraudster impersonated an FBI agent using the name “Agent Dozier Jr.”

Scammer impersonating an FBI agent using the name “Agent Dozier Jr.” (Credit: Proofpoint)

Researchers sent tracking links to the threat actors during their investigation. The resulting IP data indicated that the attackers were operating from mobile networks in Nigeria. Proofpoint said this aligns with the Nigerian links it commonly observes in advance-fee fraud operations.

The Wider Risk

Similar recruitment scams have targeted job seekers outside universities. Hackread.com has reported several recruitment scams in recent years, including a May 2025 Netcraft investigation into fake technology-company jobs that pushed victims into advance-fee schemes involving cryptocurrency.

More recently, the RecruitTrap campaign used more than 3,000 phishing URLs impersonating recruitment processes across over 50 organizations, including Amazon, Apple, Boeing, Deloitte, and Lego, to steal corporate credentials.

The Proofpoint campaign shows how these tactics become more effective when attackers first compromise a trusted university account. Proofpoint notes that MFA can prevent this type of ATO when attackers only have the stolen username and password. Universities should, therefore, enforce MFA, while students should independently verify unexpected job offers and never send money or gift cards to an alleged employer.

(Photo by Kirill Dice on Unsplash)





Source link