Proofpoint warns of university account takeover campaigns linked to job scams

Proofpoint warns of university account takeover campaigns linked to job scams

Cybercriminals are compromising US university email accounts and using them to distribute job-related advance fee fraud, according to research from Proofpoint.

The company’s researchers are tracking a cluster of activity attributed to West African fraud actors that combines credential phishing, account takeover and subsequent financial fraud.

Attacks typically begin with emails asking recipients to verify or refresh their passwords, sometimes warning that accounts could be deactivated because of retirement, graduation or transfer.

Victims are directed to forms hosted on legitimate services including Google Forms, Wix, Jotform, Zoho Forms and Microsoft Office rather than conventional phishing websites.

The forms request information including usernames, passwords and personally identifiable information, which can then be used to compromise university accounts.

Attackers subsequently use trusted .edu accounts to distribute fraudulent job or internship opportunities. These ultimately lead to advance fee fraud, demonstrating what Proofpoint describes as multi-stage monetisation rather than isolated scam activity.

Students can be particularly attractive targets because of financial pressures and their potential trust in communications originating from institutional email accounts.

Proofpoint said university accounts also provide attackers with credibility when targeting people both inside and outside an institution.

The findings demonstrate how an initial credential theft campaign can develop into further attacks by exploiting the reputation and contacts associated with a compromised university identity.

Browse our latest issue

Intelligent CISO

View Magazine Archive