Skip to content
Breaking:

Proofpoint Details Phishing Campaign Hijacking University Mailboxes for Advance Fee Scams

Attackers compromise legitimate .edu accounts to distribute counterfeit check job offers and extort students.

By The Company Wire3 min read
Share
Proofpoint — Proofpoint Details Phishing Campaign Hijacking University Mailboxes for Advance Fee Scams
Proofpoint — Proofpoint Details Phishing Campaign Hijacking University Mailboxes for Advance Fee Scams. Photo: TechRadar Pro.

Cybercriminals operating from Nigeria are hijacking legitimate university email accounts to run advance fee fraud schemes targeting students in Western institutions, according to research from security firm Proofpoint detailed by TechRadar Pro (https://www.techradar.com/pro/security/scammers-target-new-students-by-hijacking-legitimate-us-university-emails). The operation relies on compromised .edu domains to bypass skepticism and distribute counterfeit employment offers designed to steal hundreds of dollars per victim.

The multi-stage scheme begins with credential-harvesting emails sent to students, faculty, or alumni holding valid .edu addresses. These lures falsely claim the recipient's email account is slated for deactivation due to graduation, transfer, or retirement, prompting victims to enter their passwords into a fake verification portal. Once attackers gain control of an authentic mailbox, they use the trusted institutional domain to circulate fraudulent job advertisements to existing contact lists and wider directories of student addresses.

Recipients who accept the counterfeit job offers receive an image of a $1,000 check with instructions to deposit it into their personal bank account. The scammers direct the victim to keep half as a wage advance and spend the remaining $500 on retail gift cards to be transmitted back to the attackers. Because banking institutions routinely make deposited funds available before completing check clearance, victims purchase the gift cards with their own capital before the bad check is reversed, absorbing a $500 loss. Proofpoint researchers who engaged with the campaign noted that when targets hesitate, the operators escalate by proposing other payment services or placing phone calls while impersonating Federal Bureau of Investigation agents to threaten legal arrest.

Proofpoint traced the campaign's origin by tricking the perpetrators into clicking tracking links generated through the Grabify IP-logging service. Telemetry confirmed the connections originated from mobile network infrastructure in Nigeria. The security firm noted that while threat actors frequently utilize virtual private networks, advance fee fraudsters in these multi-platform campaigns regularly interact with communications from personal mobile devices, exposing their genuine network origins.

Sources

  1. TechRadar Pro

Company: Proofpoint

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.