As students across the Middle East settle into the new academic year, their inboxes fill up with messages from registrars, IT departments and prospective employers. This makes university email a valuable channel for fraudsters seeking to exploit the trust associated with institutional accounts.
A new Proofpoint analysis of the top 100 universities in the 2026 Arab Region University Rankings found that 83% have published a DMARC record, while 39% have set it to ‘reject’, the strictest level of protection. The remaining 61% have yet to enforce it fully, leaving room for fraudulent emails sent in their name to reach students, staff and partners.
Domain-based Message Authentication, Reporting and Conformance (DMARC) is an email authentication protocol that helps prevent cybercriminals from sending emails that impersonate a university’s domain. However, DMARC addresses only one part of the problem. It protects a university’s domain from being spoofed, but attackers who gain access to genuine student and staff accounts can send emails that pass authentication checks.
Proofpoint research into U.S. universities shows how compromised university accounts can become the starting point for job scams.
Case Study: From University Account Takeover to Job Scam Abuse in the U.S.
Proofpoint is tracking a cluster of threat activity specifically targeting U.S. universities.
University students, staff, and alumni are a perennial target for many different types of cybercrime, including job scams, fake scholarships, and account takeover (ATO) activities. Threat actors find higher education email accounts valuable because students may have less experience engaging with potential work or money-making opportunities, while staff and faculty routinely receive communications from a wide range of university and personal email accounts.
By gaining access to a .edu account, threat actors can use the credibility of the university domain to lend legitimacy to their scams.
Campaign Details
Campaigns typically start with an initial email lure requesting a password verification or refresh. Then, the recipient is directed to a web-based form, hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office. If the user fills out the form that usually asks for usernames, passwords, and personally identifiable information (PII), then that information is captured and sent to the threat actor to facilitate account compromise. The actor will use the compromised, trusted university account to send new emails relating to job or internship opportunities.
In addition to capturing credentials the forms also harvest a wide variety of PII such as legal name, phone numbers, university email address, and personal email addresses. This allows the threat actors to leverage personal information for follow on activity, like crafting more personal or believable lures, expanding targeting to personal inboxes, or potentially identity theft.
Account takeover can only be achieved if there is no second-factor authentication implemented.
Once they have compromised an account, the threat actors will leverage it to make money. Using the compromised email accounts, the adversary will pretend to be university staff members, or an affiliate linked to the university, and broadly distribute emails purporting to relate to job openings. Proofpoint researchers have observed a variety of different employment lures, ranging from personal concierges and remote charity staff to university research assistants and secret shoppers.
Emails contain links to the purported opportunity; however, they’re actually the same type of third-party web-based forms the actors used for phishing. But this time, these forms look like job applications.
These web forms are designed to harvest enough information from a victim that even if they cannot monetize it immediately, they have other options for monetization in the future.
Other forms ask for information such as gender, bank information, or payment accounts, in addition to personal details.
Some of the forms also bear hallmarks of LLM-generation, with repetitive lists, emoji, and generic descriptive content.
Engaging With the Scammers
To understand how threat actors monetized these scams, Proofpoint researchers engaged with a number of fraudsters directly from various campaigns. The threat actors sent fraudulent checks, typically around $1,000, instructing researchers to deposit the check and keep a portion as payment. They were then told to use the remaining funds to purchase gift cards and send the codes back to the threat actor.
When targets did not follow their instructions, the fraudsters became increasingly insistent on getting the money any way possible, suggesting Bitcoin and banking services like PayPal and CashApp, and on some occasions, they impersonated an FBI agent and threatened legal action and arrest.
Attribution
Many types of online-based crimes consistently originate in specific geographies, although not necessarily exclusively. Telephone-oriented attack delivery (TOADs) threat actors are often based in Indian call centers to enable phone-based fraud and malware delivery; pig butchering (cryptocurrency investment scams) are often based out of Southeast Asian countries including Cambodia and Myanmar. For this type of job fraud, Proofpoint researchers regularly observe geographic linkages to West African-based fraud operations, mainly in Nigeria.
Conclusion
Universities will remain a valuable target for many kinds of threat actors from espionage to cybercrime, but the good news is the fraud described in this report can be prevented. Proofpoint recommends the following:
- Require the use of multifactor authentication (MFA) on all accounts. These scammers target “low-hanging fruit” and don’t typically attempt to compromise user accounts that have MFA enabled.
- Remain vigilant about unsolicited job offers, no matter the platform or application on which it is received. These types of fraudsters often use social media and SMS in addition to email for initial outreach.
- Never provide any money to a person who claims to be an employer. While this particular scam relies on the target cashing a fraudulent check and purchasing gift cards, Proofpoint has observed other types of job fraud that attempt to steal cryptocurrency, or that ask for payment for alleged goods and services like computer equipment.
- Implement DMARC and set the policy to ‘reject’ to help prevent cybercriminals from sending emails that impersonate the university’s domain.











