Cybersecurity researchers have identified a sophisticated fraud campaign targeting U.S. universities where attackers hijack legitimate institutional email accounts to orchestrate multi-stage “job scams.” According to a report by Proofpoint, the Nigeria-based threat actors leverage the inherent trust of .edu domains to bypass email filters and deceive students into participating in fraudulent financial schemes.
The campaign relies on an attack chain where attackers use hijacked university accounts to ensure their messages appear as internal communications, significantly increasing the likelihood that students will engage with the malicious content.
The Technical Bypass: How Attackers Evade Detection
One of the most notable aspects of this campaign is the specific technical bypass used to harvest credentials. When attackers direct victims to legitimate form-hosting services like Google Forms or Wix to collect login data, they often encounter automated security filters designed to block forms that ask for “passwords.”
To circumvent these protections, researchers found that the attackers use the placeholder “WORDWORD” in the field where a password would typically be requested. This simple string substitution allows the fraudulent forms to remain active on legitimate platforms longer than those using standard terminology, effectively tricking automated scanners. Proofpoint researchers confirmed the attackers’ Nigerian origin by using Grabify IP logging links during direct engagement.

The initial breach of these university accounts is often facilitated by a lack of multi-factor authentication (MFA). Once a single account is compromised—often a student, faculty member, or even an alumnus—the attackers use that trusted platform to blast “job opportunities” for roles such as research assistants or personal shoppers to the rest of the campus community.
Mechanics of the Financial Exploitation
Students who respond to these fake job offers are quickly moved into a financial fraud cycle. Scammers send fake job offers for roles like research assistant or personal shopper using the authority of hijacked .edu domains to deceive victims.
Escalation and Law Enforcement Impersonation
The fraud cluster has demonstrated a willingness to use aggressive intimidation tactics when victims become suspicious or stop communicating. Reported claims indicate that attackers have impersonated federal agents, including FBI personnel, over the phone to threaten victims with arrest if they stop communicating.
This surge in impersonation tactics mirrors broader trends. The Internet Crime Complaint Center (IC3) documented nearly 61,000 complaints involving the impersonation of law enforcement between January 2025 and July 2026.
To protect themselves, students and faculty are advised to verify any unsolicited campus job offer by contacting the specific department through a phone number listed on the official university directory—never the contact information provided in the email. Furthermore, university IT departments are urged to enforce MFA across all accounts, including those for alumni, which are frequently targeted due to lower security monitoring.
















