Proofpoint Details Phishing Campaign Hijacking University Mailboxes for Advance Fee Scams
Attackers compromise legitimate .edu accounts to distribute counterfeit check job offers and extort students.

Cybercriminals operating from Nigeria are hijacking legitimate university email accounts to run advance fee fraud schemes targeting students in Western institutions, according to research from security firm Proofpoint detailed by TechRadar Pro (https://www.techradar.com/pro/security/scammers-target-new-students-by-hijacking-legitimate-us-university-emails). The operation relies on compromised .edu domains to bypass skepticism and distribute counterfeit employment offers designed to steal hundreds of dollars per victim.
The multi-stage scheme begins with credential-harvesting emails sent to students, faculty, or alumni holding valid .edu addresses. These lures falsely claim the recipient's email account is slated for deactivation due to graduation, transfer, or retirement, prompting victims to enter their passwords into a fake verification portal. Once attackers gain control of an authentic mailbox, they use the trusted institutional domain to circulate fraudulent job advertisements to existing contact lists and wider directories of student addresses.
Recipients who accept the counterfeit job offers receive an image of a $1,000 check with instructions to deposit it into their personal bank account. The scammers direct the victim to keep half as a wage advance and spend the remaining $500 on retail gift cards to be transmitted back to the attackers. Because banking institutions routinely make deposited funds available before completing check clearance, victims purchase the gift cards with their own capital before the bad check is reversed, absorbing a $500 loss. Proofpoint researchers who engaged with the campaign noted that when targets hesitate, the operators escalate by proposing other payment services or placing phone calls while impersonating Federal Bureau of Investigation agents to threaten legal arrest.
Proofpoint traced the campaign's origin by tricking the perpetrators into clicking tracking links generated through the Grabify IP-logging service. Telemetry confirmed the connections originated from mobile network infrastructure in Nigeria. The security firm noted that while threat actors frequently utilize virtual private networks, advance fee fraudsters in these multi-platform campaigns regularly interact with communications from personal mobile devices, exposing their genuine network origins.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



