Higher Education

From EDU Account Takeover to Job Scam Abuse: West African Fraud Actors Target Universities

Share with your network!

Key Takeaways

  • Threat actors are using compromised university email accounts to distribute job-based advanced fee fraud.
  • College students are uniquely vulnerable due to financial pressure and trust in institutional email.
  • Threat actors leverage form-based credential harvesting rather than traditional, web-based phishing kits.
  • These campaigns demonstrate multi-stage monetization, not isolated scam activity.

Overview

Proofpoint is tracking a cluster of threat activity specifically targeting U.S. universities. The fraud ecosystem observed in campaigns aligns with known advance fee fraud (AFF) tactics.

The campaigns begin with credential harvesting attempts that lead to job scam monetization leveraging AFF.

University students, staff, and alumni are a perennial target for many different types of cybercrime, including job scams, fake scholarships, and account takeover (ATO) activities. Threat actors find higher education email accounts valuable for a variety of reasons including: younger students may have less experience with email correspondence and are new to engaging with potential work or money-making opportunities; alumni may still have active email accounts, but may not use them frequently, providing an opportunity for threat actors to hijack their contact lists; and staff and faculty are constantly receiving communications from students, parents, community members, etc. from a variety of personal and university emails. By gaining access to a .edu account, threat actors can use the authority of the TLD to lend credibility to their scams both inside and outside of the target organization.

In this report, we’ll highlight two different cybercrimes conducted by the same threat actors, revealing an attack chain that uses credential phishing to facilitate fraud targeted at university affiliated individuals. By understanding the entire attack chain, organizations can better educate users, improve detections, and potentially disrupt ongoing activity.

Campaign Details

Campaigns typically start with an initial email lure requesting a password verification or refresh. Then, the recipient is directed to a web-based form, hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office. If the user fills out the form that usually asks for usernames, passwords, and personally identifiable information (PII), then that information is captured and sent to the threat actor to facilitate account compromise. The actor will use the compromised, trusted university account to send new emails relating to job or internship opportunities. These ultimately lead to AFF.

The initial lures aim to entice a wide range of university targets. Topics include a broad-based threat of account deactivation due to “retirement, graduation, or transfer.” The email directs the potential victim to fill out a web form on a third-party website.

image-20260928152317-1

Figure 1: “Account deactivation” lure.

Many of these form submission websites implement word filtering on forms to prevent users from entering sensitive information such as passwords. As a result, the threat actors often avoid explicitly including terms like “password” in the form fields. Instead, they guide or coach the victim on which field should be used to enter their password. In the example above, they use the descriptive placeholder “WORDWORD” in place of the word “password.”

                  “Note: ‘WORDWORD’ in the form refers to your password.”

In addition to capturing credentials the forms also harvest a wide variety of PII such as legal name, phone numbers, university email address, and personal email addresses. This allows the threat actors to leverage personal information for follow on activity, like crafting more personal or believable lures, expanding targeting to personal inboxes, or potentially identity theft. The form does not actually reset or update anything. The victim believes they've completed a routine IT task. The attacker now has valid credentials.

It’s worth noting the actors are not using more advanced credential capture techniques like attacker-in-the-middle (AiTM) phishing for multifactor authentication credential theft, or device code phishing. In these cases, ATO can only be achieved if there is no second-factor authentication implemented.

image-20260928152317-2

Figure 2: Credential Harvesting Form with WORDWORD standing in for PASSWORD.

image-20260928152317-3

Figure 3: Fake university form.

image-20260928152317-4

Figure 4: Fake university form.

image-20260928152317-5

Figure 5: Fake university form.

Once they have compromised an account, the threat actors will leverage it to make money. Using the compromised email accounts, the adversary will pretend to be university staff members, or an affiliate linked to the university, and broadly distribute emails purporting to relate to job openings. Proofpoint researchers have observed a variety of different employment lures, ranging from personal concierges and remote charity staff to university research assistants and secret shoppers.

Emails contain links to the purported opportunity, however they’re actually the same type of third-party web-based forms the actors used for phishing. But this time, these forms look like job applications.

image-20260928152317-6

Figure 6: Job scam email lure for a “remote personal assistant”.

Like the credential harvesting forms, these web forms are designed to harvest enough information from a victim that even if they cannot monetize it immediately, they have other options for monetization in the future.

image-20260928152317-7

Figure 7: Job description on the web form.

image-20260928152317-8

Figure 8: Promises of remote work and competitive benefits on the form.

image-20260928152317-9

Figure 9: Harvesting Personally Identifiable Information.

The fraudulent landing pages and related forms feature a wide variety of different themes and designs, depending on the topic. Some collect only emails, passwords, and PII, like the example below:

image-20260928152317-10

Figure 10: “Errand runner” job application.

While others ask for information such as gender, bank information, or payment accounts, in addition to personal details.

image-20260928152317-11

Figure 11: “Secret shopper” and “personal assistant” job application with mailing address, bank, and gender questions.

Some of the forms also bear hallmarks of LLM-generation, with repetitive lists, emoji, and generic descriptive content. It is unlikely the use of AI changes the likelihood of engagement or efficacy of the campaign, but may reduce the amount of time the threat actors spend creating malicious webpages.

image-20260928152317-12

Figure 12: AI-generated fake “virtual admin” job application.

Engaging With The Scammers

To understand how threat acters monetized these scams, Proofpoint researchers engaged with a number of fraudsters directly from various campaigns. Each time the scenario was very similar:

  • The threat actors first told the researchers to submit a resume via email. Then, they asked follow-up questions including, “Do you have access to a printer?” and “Do you have mobile banking?”
  • Once these questions were answered to the scammer’s satisfaction, the threat actors emailed a scanned copy of a check (on average about $1000). They instructed the victim to do a mobile deposit and to keep a portion (typically about half) as payment for their first week of employment.
  • For the rest of the “earnings”, the target is instructed to purchase gift cards in $100 increments. This is to avoid some retail stores’ anti-fraud efforts.
  • Finally, targets are then told to send the gift card codes back to the threat actor.

If the target did not follow their instructions, threat actors became increasingly insistent on getting the money any way possible, suggesting Bitcoin and banking services like PayPal and CashApp. When they did not receive the money, they became hostile and started texting and calling from multiple different phone numbers asking for updates of when they would get paid. After still not receiving their payment, the fraudsters resorted to threats. On one occasion, they impersonated an FBI agent and threatened legal action and arrest.

image-20260928152317-13

Figure 13: Threat actor engagement with Proofpoint researcher.

image-20260928152317-14

Figure 14: Threat actor escalation with Proofpoint researcher.

image-20260928152317-15

Figure 15: Text message from the scammers claiming to be an “FBI agent” named “Agent Dozier Jr.” This name, which is real, and this unrelated person’s image, have previously been used by various fraudsters and shared widely on the internet.

Attribution

Many types of online-based crimes consistently originate in specific geographies, although not necessarily exclusively. Telephone-oriented attack delivery (TOADs) threat actors are often based in Indian call centers to enable phone-based fraud and malware delivery; pig butchering (cryptocurrency investment scams) are often based out of Southeast Asian countries including Cambodia and Myanmar. In the case of AFF, Proofpoint researchers regularly observe geographic linkages to West African-based fraud operations, mainly in Nigeria.

During engagements with the university-targeting threat actors, in which we pretend to be a victim to understand the full attack chain, Proofpoint researchers sent several tracking links to them via Grabify. The fraudsters thought they were chatting with a real victim. Grabify is an IP logging and URL shortening service used by online marketers. These links are used to extract information such as device information and IP addresses. When the scammers clicked the links, our researchers could see where they were clicking from. Each engagement found these threat actors’ operations to be in Nigeria. While it is possible for threat actors to spoof their infrastructure, based on our investigations from hundreds of engagements, these AFF fraudsters typically use their real mobile network infrastructure to conduct their crimes. Even if the scammers do use a VPN, they often still click on researchers’ links from their genuine devices due to the multi-platform communication style they use (and the desire to monetize, despite possible deanonymization).

image-20260928152317-16

Figure 16: One example of an IP that conducted fraudulent activity.

image-20260928152317-17

Figure 17: Geographic data relating to an IP that conducted fraudulent activity.

image-20260928152317-18

Figure 18: Information related to an IP that conducted fraudulent activity.

Conclusion

Universities will remain a valuable target for many kinds of threat actors from espionage to cybercrime, but the good news is the fraud described in this report can be prevented. Proofpoint recommends the following:

  • Require the use of multifactor authentication (MFA) on all accounts. AFF scammers target “low-hanging fruit” and don’t typically attempt to compromise user accounts that have MFA enabled.
  • Remain vigilant about unsolicited job offers, no matter the platform or application on which it is received. These types of fraudsters often use social media and SMS in addition to email for initial outreach.
  • Never provide any money to a person who claims to be an employer. While this particular scam relies on the target cashing a fraudulent check and purchasing gift cards, Proofpoint has observed other types of job fraud that attempt to steal cryptocurrency, or that ask for payment for alleged goods and services like computer equipment.