securityonline.info 30 Sept 2026, 08:00 UTC

Nigerian Fraudsters Hijack .edu Accounts for University Job Scams

IN a UK-facing write‑up of Proofpoint research, Nigerian-linked fraudsters are described as hijacking .edu accounts to push university job scams across the United States. The operation begins with credential phishing aimed at stealing login details, then using those accounts to send fake job offers to students, staff and alumni.

The scams employ forms hosted on trusted platforms (Google Forms, Wix, Jotform, Zoho, Microsoft Form) that apparently can bypass word filters by instructing victims to enter their password in a field labeled WORDWORD. The captured credentials are typically from accounts lacking multifactor authentication, enabling the attackers to access active university inboxes.

Proofpoint’s investigation then follows the chain to a “job” stage, where victims receive offers for roles such as research assistant or secret shopper. The deception continues with additional forms requesting personal details, and in some cases bank details. The final step is a check‑based payout: researchers traced a process in which victims deposit a scanned check worth about $1,000 and are told to use roughly half for pay while the rest is funneled to gift cards before card codes are returned.

In some instances the scammers tried alternative payment routes or impersonated officials. The report notes the broader impact includes reputational harm to universities and that victims may face the burden of repaying banks; it also highlights that alumni accounts are particularly risky. Suggested mitigations include mandating MFA on university accounts, treating unsolicited job offers with suspicion, never depositing unfamiliar checks, and reporting suspected offers to campus IT and FTC’s ReportFraud.

View full article

Article by CyberSIXT