Text message from the scammers
A fake IT form told students to type their password into a field labeled “WORDWORD.” The trick dodged the form site’s word filter, and it worked. According to Proofpoint’s research on .edu account takeover and job scam abuse, those stolen logins now power a wave of university job scams across the United States.
At a Glance
| Actor | Unnamed advance fee fraud cluster, suspected to operate from Nigeria |
| Activity | Credential phishing, .edu account takeover, fake job offers, check fraud |
| Targets | Students, staff, faculty, and alumni at U.S. universities |
| Scale | Fake checks of about $1,000 each (observed in researcher engagements); victim totals not disclosed |
| Law enforcement | No arrests or charges announced |
| Sources | Proofpoint Threat Research; U.S. Federal Trade Commission |
TL;DR
Fraudsters steal university email logins with simple web forms. They then use those trusted accounts to send fake job offers to students. The “jobs” end with a bogus check and a demand for gift cards.
What Happened
Stage One: Stealing the Account
The scam starts with an email about account shutdown. The lure warns of deactivation due to “retirement, graduation, or transfer.” Next, it sends the reader to a form hosted on a trusted service. Proofpoint saw Google Forms, Wix, Jotform, Zoho Forms, and Microsoft Office forms in use.
These form sites often block the word “password.” So the attackers coach victims instead. One form told users, “Note: ‘WORDWORD’ in the form refers to your password.” The form also grabs names, phone numbers, and personal email addresses. Meanwhile, the victim thinks they finished a routine IT task.
Notably, the actors do not use advanced phishing kits. As a result, their stolen passwords only work on accounts without multifactor authentication.
Stage Two: The Fake Job
With a real .edu inbox in hand, the fraudsters pose as university staff. They send job offers for roles such as research assistant, personal concierge, or secret shopper. The links lead to more web forms, now dressed up as job applications. Some forms ask for bank details, mailing addresses, and payment accounts.
Proofpoint also found signs of AI-written pages, with emoji and repetitive lists. However, the researchers doubt this makes the lures more convincing. Instead, it likely just saves the scammers time.
Stage Three: The Check Scam
Proofpoint researchers posed as victims to follow the full chain. First, the scammers asked for a resume. Then came two telling questions: “Do you have access to a printer?” and “Do you have mobile banking?”
After that, the fraudsters emailed a scanned check worth about $1,000. They told the target to deposit it by phone and keep roughly half as pay. The rest had to go toward gift cards in $100 amounts. Eventually, the target would send the card codes back.
When researchers stalled, the pressure grew. The scammers pushed Bitcoin, PayPal, and CashApp. They called and texted from several numbers. In one case, they even posed as an FBI agent and threatened arrest.
Who Is Behind It
Proofpoint links this activity to West African advance fee fraud, mainly in Nigeria. During engagements, researchers sent the scammers tracking links. Each click traced back to Nigeria. Proofpoint admits that actors can spoof their location. Still, based on hundreds of past engagements, it says these fraudsters “typically use their real mobile network infrastructure.”
This counts as a moderate-confidence, research-based link. No authority has named or charged any suspect.
Impact and Scale
Proofpoint did not publish victim counts or total losses. However, the harm to each victim can be steep. The fake check bounces days later. By then, the gift card money is gone. The U.S. Federal Trade Commission warns that victims must repay the bank themselves.
The stolen .edu accounts also cause wider damage. Each one lends the university’s name to more university job scams. Alumni accounts are a special risk, since owners rarely check them.
How to Stay Protected
Fortunately, Proofpoint says this fraud “can be prevented.” Schools and students can take these steps:
- Require MFA on every university account. These fraudsters target “low-hanging fruit” and rarely attack MFA-protected users.
- Treat any unsolicited job offer as suspect, even from a .edu address.
- Never deposit a check from a new employer and send money onward.
- Never buy gift cards or crypto for someone claiming to be your boss.
- Report suspicious offers to your campus IT team and to ReportFraud.ftc.gov.
The FTC puts the core rule simply: “If a new employer mails your first paycheck before you even start working, that’s your cue to stop.” In the end, a real employer pays you. It never asks you to pay it back.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!