AI News Feed
Market watch
Cybersecurity

Scammers Hijack US University Emails to Target New Students With Fake Jobs and Gift Cards

Proofpoint says a Nigeria-linked scam campaign is using stolen .edu accounts to send fake job offers and gift-card requests, leaving victims $500 short after fake checks are reversed.

Proofpoint said it did not know how many people had fallen victim or how long the operation had been running. The campaign is multi-stage, beginning with a phishing email sent to an .edu address. The message warns that the account will be deactivated for a made-up reason such as retirement, graduation or transfer, then asks the recipient to verify the address and share their password.

After gaining access, the criminals use the stolen account to send a second phishing email to contacts in the address list and to other .edu addresses. That message advertises a fake job for students. Those who are told they have been hired receive a copy of a $1,000 check and are instructed to deposit it. They are told to keep half as their salary and use the other half to buy gift cards, which they should send back to the scammers.

The checks are fake. By the time the bank discovers the scam, the victim has already bought and sent the gift cards. The bank then reverses the deposit, leaving the victim $500 short. If a victim does not follow the instructions, the scammers become aggressive, suggest different payment services and even call the person by phone while pretending to be an FBI agent threatening legal action and arrest.

Proofpoint researchers were “hired” for one of the jobs, which is how they uncovered the operation. The researchers said attributing the scam to a particular group is difficult, but they tricked the fraudsters into using Grabify, an IP logging and URL shortening service normally used by online marketers. Such links can extract device information and IP addresses from anyone who clicks them, and Proofpoint found engagement coming from Nigeria.

Proofpoint said it was confident about the location of this operation. “While it is possible for threat actors to spoof their infrastructure, based on our investigations from hundreds of engagements, these AFF fraudsters typically use their real mobile network infrastructure to conduct their crimes,” the researchers concluded. The report added that even when scammers use a VPN, they often still click on researchers’ links from genuine devices because of their multi-platform communication style and their desire to monetize the scheme despite possible deanonymization.

Proofpoint also explained why the scammers focus mainly on college students. Younger students may have less experience with email correspondence and may be new to engaging with potential work or money-making opportunities. Alumni may still have active email accounts but may not use them frequently, giving threat actors a chance to hijack their contact lists. Staff and faculty constantly receive communications from students, parents, community members and others through personal and university emails. By gaining access to a .edu account, the researchers said, threat actors can use the authority of the academic domain to lend credibility to their scams both inside and outside the target organization.