Share
UNIVERSITY EMAIL - ADVANCE FEE FRAUD

The job email came from a real university address. So why did it ask about your printer?

Proofpoint traced a campus job scam where every trust signal is genuine, because the account sending it was phished first. The tell is not the sender. It is a screening question no employer would ask.

SafeBrowz Threat Research Security Research · · 10 min read

The Brief

A job or internship offer arrives from a genuine university email address, often someone at your own institution. It is real because the account was stolen first. Proofpoint published the chain on 28 September 2026: it usually opens with an email asking you to verify or refresh your password, that form is hosted on a legitimate service, and the logins it captures are what turn real university mailboxes into the senders of the job offers. If you reply, you are asked for a resume and then two questions that give the whole thing away, "Do you have access to a printer?" and "Do you have mobile banking?". A scanned counterfeit check, on average about $1,000, follows. You deposit it, keep a slice as wages, and buy gift cards in $100 increments with the rest. Two checks actually work here: treat a payment that arrives before any work as the fraud itself, and confirm the role through the university's own website rather than through the thread. If the email does carry a link, check it before you type a password, but know that a form built on a household-name platform can come back clean because the host genuinely is trustworthy. Nothing you can see in the sender will help you.

The sender is authentic and the form is on a real platform, so reputation tells you nothing. The request is what gives it away. Add to Chrome, free Get the free Android app or scan a URL now →

Every warning sign you were taught to look for is missing

Campus security advice is built on a short list. Check the sender's address. Look for the misspelled domain. Be suspicious of a free email account pretending to be an institution. All of it is sound, and in this campaign all of it passes.

Proofpoint, which published its analysis of the activity on 28 September 2026, is direct about why. The report states that the actor will use "the compromised, trusted university account to send new emails relating to job or internship opportunities". The address is not a lookalike. It is not a spoof. It belongs to the university, and frequently to a real person at it, because somebody at that institution was phished in an earlier stage of the same operation.

That has a consequence worth being blunt about. Every technical check a mail system performs on the sending domain will come back clean, because the mail genuinely originates from the institution it claims to. There is no authentication failure to catch. The message is not forged, it is sent by the rightful owner's account in the wrong hands.

We have written before about what happens when the sender is a real account someone else is driving, and the lesson transfers exactly: advice built on "does this account look legitimate" stops working the moment the account is legitimate. The difference here is the population. The people receiving these messages are students, often new ones, who have every reason to expect unfamiliar university staff to email them about money.

Stage one: the form is not on a phishing site

The credential theft that makes the rest possible does not happen on a cloned login page with a suspicious address. Proofpoint describes the recipient being directed to "a web-based form, hosted on legitimate services like Google forms, Wix, Jotform, Zoho Forms, and Microsoft Office".

Read that list again, because it is the engineering decision at the centre of this. docs.google.com, jotform.com and Microsoft's own form builder are not scam infrastructure. They are products with millions of honest users, excellent reputations, valid certificates and long-established domains. A form built on one of them inherits all of that for free, and it takes about two minutes to build with a free account.

So the usual instruction, look at the address bar, produces a reassuring answer. The address really is Google's. The padlock really is valid. What is being asked for on the page is the part that is wrong, and the page is the only place that information lives.

This is the same structural problem as a credential form on a platform people already trust, and it is why a verdict that reads only the domain is not enough on its own. The form asks for usernames, passwords and personal details. Those logins are what produce the next wave of trusted senders, which is why Proofpoint frames this as multi-stage monetisation rather than a one-off scam.

Stage two: a stranger's inbox becomes the mailing list

With a working set of university credentials, the operation stops needing to look convincing, because it now is. The compromised mailbox sends job and internship offers, and they land from an address that genuinely belongs to the institution. Proofpoint describes the adversary using those accounts to "pretend to be university staff members, or an affiliate linked to the university", so the display name may be invented even though the address is not.

Proofpoint notes that "university students, staff, and alumni are a perennial target for many different types of cybercrime, including job scams, fake scholarships, and account takeover (ATO) activities", and this campaign chains two of those categories together. The account takeover is not the goal. It is the delivery system for the job scam, and the job scam is the thing that takes the money.

On attribution, the report is careful and so is this post. Proofpoint says that for this class of fraud its researchers "regularly observe geographic linkages to West African-based fraud operations, mainly in Nigeria", and that in its own engagements with the actors, "each engagement found these threat actors' operations to be in Nigeria". That is a finding about where these particular operators were traced to, not a label for a country.

The two questions that reveal what the job actually is

Proofpoint's researchers engaged with the scammers directly, which is why the script is documented rather than guessed at. The threat actors first asked for a resume by email, which is ordinary enough to lower anyone's guard. Then came the part that is not ordinary at all. The report records the follow-up questions as "Do you have access to a printer?" and "Do you have mobile banking?".

Sit with how strange that is. No employer on earth needs to know whether a candidate owns a printer before deciding to hire them. Those two questions are not screening you for the job. They are confirming you have the two pieces of equipment the fraud requires: something to print a counterfeit check on, and an app that will deposit it without a human being looking at the paper.

If you remember one thing from this page, make it that. The strangeness of the question is the signal, and it arrives before any money is mentioned, which makes it the earliest point at which you can walk away having lost nothing.

The check that clears, and then does not

Proofpoint records what follows: "once these questions were answered to the scammer's satisfaction, the threat actors emailed a scanned copy of a check (on average about $1000)". You print it, deposit it through the banking app, and within a day or two the money shows up in your balance.

It is worth being precise about why that is not proof of anything, because this is where most victims decide the job is real. Funds appearing in your available balance is your bank advancing you money on an uncleared deposit. It is a requirement placed on banks, not a verdict on the check. The check can be returned as counterfeit well after the money looked spendable, and when it is, the credit is reversed and the shortfall is yours.

The instructions are built around that gap. You keep a portion as your first payment, which is the part that makes it feel like employment, and for the remainder Proofpoint says "the target is instructed to purchase gift cards in $100 increments" and then "targets are then told to send the gift card codes back to the threat actor". The size of those increments is not arbitrary, and the report gives the reason: "This is to avoid some retail stores' anti-fraud efforts." Split small enough, each purchase stays under the limits and flags stores put on gift-card sales. Once the codes are spent the money is unrecoverable, which is why the pressure to buy and send them quickly is relentless, and also why reporting the cards to their issuer only helps if you get there before the scammer drains them.

The shape is identical to the overpayment fraud that runs through fake remote-job equipment deposits and gift card instructions delivered by phone. Money arrives first, you are asked to move part of it onward, and the arrival is reversible while the onward payment is not.

Proofpoint also notes this is one monetisation path among several, observing "other types of job fraud that attempt to steal cryptocurrency, or that ask for payment for alleged goods and services like computer equipment". The check is the version aimed at students, because a student is likely to have a bank app and unlikely to have seen a counterfeit check before.

When you stop cooperating, the phone calls start

The ending is the part worth warning people about in advance, because it is designed to arrive when someone is already frightened and least able to think.

When a target hesitates, the pressure escalates. Proofpoint records that the actors suggested alternative payment services, and that "on one occasion, they impersonated an FBI agent and threatened legal action and arrest". The report adds a detail that says a great deal about how these operations are assembled: the agent's name and photograph belong to a real and entirely unrelated person, and have been reused by various fraudsters and circulated widely online. We are not repeating the name here, because that person is a victim of this too and has no part in it.

The reversal is the cruel bit. A student who deposited a counterfeit check has done something that genuinely looks bad on a bank statement, so a threat of arrest does not feel absurd. It feels like the obvious consequence. That is precisely why it works, and precisely why the right response is the opposite of what the caller wants: stop, keep everything, and talk to your own bank and university rather than to them. Our guide to voice and phone fraud covers the wider pattern of authority impersonation by phone.

The form is the only step a scanner can see

Being honest about where a link check helps matters more than overstating it, so here is the real picture across the three stages.

At the first stage there is a URL, so a check has something to work with, and the result depends on which platform the form sits on. Where a page is published on a user subdomain of a site builder, or on a path under sites.google.com, it is assessed as user-published content rather than inheriting the platform's reputation, and the AI layer reads what the page actually asks for in over 100 languages. A form demanding a university username and password to apply for a job is a very different object from a booking form, and that difference lives in the content, not the domain.

The limit is worth stating rather than glossing, because it affects the most likely link in this campaign. Some of the biggest document and form platforms are trusted at the domain level, deliberately, so that ordinary work files do not get flagged all day. A form hosted under such a host can therefore come back clean on the strength of the host alone. That is a reasonable trade for the sheer volume of legitimate documents shared every hour, and it is exactly the property the operators in this campaign are renting. So do not read a clean verdict on a big-platform form as confirmation that the form is honest. Read it as confirmation that the host is real, which was never the question.

At the second stage there is nothing to scan. The email is real mail from a real account, and if the message is plain text asking for a resume, there is no address in it at all. No URL checker, ours included, can help with a sentence. That stage is defended by noticing the request, which is why the printer question matters so much.

At the third stage the money has already moved and the problem is a banking one, not a browsing one. The honest scope is narrow and worth saying plainly: we can tell you what a page is before you type into it, and we cannot tell you whether a check in your hand is good. If you have reached the gift card stage, the recovery steps are more use to you than any scanner.

🛡 LIVE CHECK

Is that application form really your university's?

Paste the link from the email before you enter a single login detail. Our 3-layer engine (Local + APIs + AI) checks the host, the lists, and, where the page is ours to read, what it actually asks for. About 3 seconds, free, no signup, and no browsing history kept against you.

Full scan with deep AI analysis → · No URL is logged to your identity.

Thirty seconds that settle a campus job email

Before you reply, run these four. None of them needs a security background.

  • Was there an application you remember making? An unsolicited offer of paid work you did not apply for is the single most reliable signal, and it costs nothing to notice.
  • Does any question have nothing to do with the work? Printer access, banking apps and which payment services you use are logistics for a fraud, not for a job.
  • Is money arriving before work happens? Legitimate employers pay after work, through payroll, and never ask a new hire to forward part of a payment onward.
  • Verify through the institution, not the thread. Look up the department on the university's own website and ask them directly whether the role exists. If the account was stolen, the real owner will want to know, and if the sender invented the role, the step ends it.

If the email contains a link to an application form, checking it takes a few seconds and on most platforms tells you what the page wants before you give it anything. If you are new to spotting this family of fraud, the guide to fake job offers is the broader version, and the fake recruiter coding test covers the variant aimed at graduating developers.

Frequently asked questions

Is a job offer sent from a real university email address safe?

Not on its own. In the campaign Proofpoint documented on 28 September 2026, the account doing the sending genuinely belongs to the university, because it was phished first. The report says the actor will use the compromised, trusted university account to send new emails relating to job or internship opportunities. That means the address is real, the domain is real, and every authentication check the message passes, it passes honestly. Judge what the message asks you to do, not who it appears to come from.

Why would a job application ask whether I have a printer?

Because printing is a step in the fraud, not a step in the job. Proofpoint records the screening questions as "Do you have access to a printer?" and "Do you have mobile banking?", and notes that once these were answered to the scammer's satisfaction, the threat actors emailed a scanned copy of a check, on average about $1000. The printer is for the counterfeit check and the mobile banking app is how it gets deposited without a teller looking at it. A real employer has no reason to ask either question before hiring you.

The check cleared in my account, so was it real?

No. Money appearing in your balance is your bank making funds available, not your bank confirming the check is good, and those are different events that can be days apart. When the check is returned as counterfeit the amount is reversed and you owe it, including whatever you already spent on gift cards. That is why the instruction is always to buy and send the codes quickly.

Someone claiming to be an FBI agent called about this. What now?

It is part of the same script. Proofpoint reports that on one occasion the actors impersonated an FBI agent and threatened legal action and arrest, and that the name and photo used belong to a real, unrelated person and have been reused by various fraudsters. Law enforcement does not phone you to demand payment or to pressure you into finishing a transaction. Stop replying, keep the messages, and report it to your university IT team and to the FBI at ic3.gov yourself.

What should I do if I already deposited the check and bought gift cards?

Call your bank immediately and tell them you believe you deposited a counterfeit check, because the sooner they know the better your position when it is returned. Report the gift cards to the issuer, as some can freeze a card before the balance is drained if the codes have not been used yet. Then tell your university IT team, since your own account may have been phished in the first stage, and file a report at ic3.gov. Keep every email, text and screenshot.

Follow on Google