{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/higher-education/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Google Forms","Wix Forms","Jotform","Zoho Forms","Microsoft Office"],"_cs_severities":["medium"],"_cs_tags":["phishing","fraud","advance-fee-fraud","higher-education","social-engineering"],"_cs_type":"advisory","_cs_vendors":["Google","Wix","Jotform","Zoho","Microsoft"],"content_html":"\u003cp\u003eProofpoint researchers have identified a campaign by West African-based fraud actors targeting U.S. universities. The threat actors compromise .edu email accounts through credential harvesting lures, which they then use to distribute job-related advance fee fraud (AFF). The actors exploit the inherent trust associated with institutional email addresses to deceive students, staff, and alumni.\u003c/p\u003e\n\u003cp\u003eRather than deploying custom phishing kits, the actors utilize legitimate form-building services, including Google Forms, Wix, Jotform, Zoho Forms, and Microsoft Office, to capture credentials and personally identifiable information (PII). By avoiding the use of explicit keywords like \u0026quot;password\u0026quot; in form fields, attackers attempt to bypass simple automated filters. Once an account is compromised, it is used to send legitimate-looking emails detailing fake job opportunities. Victims are subsequently coerced into mobile check deposits and the purchase of gift cards. The threat actors exhibit aggressive tactics, including threats of legal action and impersonation of law enforcement, if targets fail to comply with the financial demands.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a phishing email to university targets claiming an account must be refreshed due to graduation or retirement.\u003c/li\u003e\n\u003cli\u003eThe email redirects the victim to a legitimate third-party form provider (e.g., Google Forms, Jotform).\u003c/li\u003e\n\u003cli\u003eThe victim provides account credentials and PII into the hosted form, bypassing filters by following attacker instructions (e.g., using \u0026quot;WORDWORD\u0026quot; as a placeholder for password).\u003c/li\u003e\n\u003cli\u003eThe actor logs into the victim's university account using the harvested credentials.\u003c/li\u003e\n\u003cli\u003eThe compromised account is used to send bulk emails impersonating faculty or staff, advertising fake remote job opportunities.\u003c/li\u003e\n\u003cli\u003eVictims interact with a second set of malicious forms that harvest personal and financial details.\u003c/li\u003e\n\u003cli\u003eThe actor engages the victim via email or phone, instructing them to deposit a fraudulent check and purchase gift cards for \u0026quot;employment\u0026quot; costs.\u003c/li\u003e\n\u003cli\u003eIf the victim resists, the actor escalates to threats, impersonation of law enforcement, or harassment to force payment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign facilitates significant financial loss for university-affiliated victims through advance fee fraud. Compromised university accounts are used to maintain persistence and establish credibility for broader scam distribution. The aggregation of PII allows for secondary identity theft and more targeted future social engineering. While the number of victims is not explicitly stated, the broad nature of the campaign indicates a high-volume attempt to leverage institutional trust.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams to mitigate this threat:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce mandatory multi-factor authentication (MFA) across all university accounts to prevent account takeover via credential phishing.\u003c/li\u003e\n\u003cli\u003eImplement email filtering policies that flag or block emails containing links to common third-party form builders when sent from external sources or suspicious internal accounts.\u003c/li\u003e\n\u003cli\u003eEducate the user base on the indicators of job-based advance fee fraud, specifically the request for mobile check deposits followed by gift card purchases.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous login behavior or mass-emailing activity originating from internal .edu accounts, which may indicate an account compromise.\u003c/li\u003e\n\u003cli\u003eInvestigate any reported \u0026quot;IT\u0026quot; communications that direct users to generic, third-party form-hosting websites rather than official university authentication portals.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T10:23:29Z","date_published":"2026-09-29T10:23:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-west-african-edu-fraud/","summary":"West African threat actors are leveraging compromised university email accounts to distribute job-based advance fee fraud by harvesting credentials via legitimate third-party form services.","title":"West African Fraud Actors Targeting Universities via Compromised .edu Accounts","url":"https://feed.craftedsignal.io/briefs/2026-09-west-african-edu-fraud/"}],"language":"en","title":"CraftedSignal Threat Feed - Higher-Education","version":"https://jsonfeed.org/version/1.1"}