West African fraud actors targeted U.S. universities with credential-phishing emails posing as account-deactivation notices, harvesting credentials and personal information through third-party form services. They then used compromised .edu accounts to send credible-looking job and internship offers to students, staff, alumni, and external recipients, exploiting institutional trust to support an advance-fee fraud scheme.
Victims who responded received fraudulent checks, often for about $1,000, and were told to deposit them, retain a portion as wages, and send the remaining funds through gift cards or other payments. Operators escalated pressure through calls, texts, threats, and one reported impersonation of an FBI agent. Proofpoint linked observed activity to Nigerian mobile networks through tracking telemetry, while cautioning that infrastructure-based attribution can be obscured; enforcing MFA would disrupt the observed phishing-to-account-takeover chain because the campaign did not use techniques designed to bypass MFA.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Proofpoint used tracking links in direct engagements and observed every investigated operator accessing them from Nigeria; related reporting described Nigerian mobile-network activity. The company assessed the university-targeting advance-fee fraud as linked to Nigerian operations while noting that infrastructure attribution can be obscured.
During engagements with Proofpoint researchers, the fraudsters escalated through repeated calls and text messages when payment was refused. In one case, an operator impersonated an FBI agent identified as “Agent Dozier Jr.” and threatened arrest or legal action.
The actors used hijacked .edu accounts to send credible-looking fake job and internship offers to university communities and external recipients. Targets who engaged were sent fraudulent checks averaging about $1,000 and pressured to send gift-card codes or alternate payments after depositing the checks.
Threat actors targeted U.S. university students, staff, and alumni with account-deactivation phishing lures, directing victims to credential- and PII-harvesting forms on legitimate third-party services. Stolen credentials were used to take over university email accounts where MFA was not enabled.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.