University of Iowa warns community over phishing and fake job scams

University of Iowa warns community over phishing and fake job scams

The University of Iowa has warned students and staff to be alert to social engineering attacks using fake Microsoft 365 security warnings and fraudulent job opportunities to steal credentials, financial information and other sensitive data.

The University of Iowa is warning students and staff about social engineering scams designed to exploit busy members of its community through urgent account warnings and attractive job offers.

The university’s Information Technology Services (ITS) said attackers are using familiar logos, names, job titles and campus terminology to make fraudulent communications appear legitimate.

One technique involves emails claiming that a recipient’s Microsoft 365 account has been terminated, exceeded its storage allowance or requires immediate verification.

Victims can then be directed to convincing sign-in pages designed to capture their university HawkID and password. Attackers may subsequently attempt to persuade the victim to approve an unexpected Duo multi-factor authentication request.

Phishing emails can also impersonate University of Iowa support teams or other university departments.

Students and staff who receive suspicious account notifications are being advised not to follow links within the message. Instead, the university recommends accessing the relevant service independently through a trusted bookmark or known website address.

ITS has also highlighted fraudulent employment opportunities targeting the university community.

These scams can advertise flexible remote positions involving activities such as working as a personal assistant, rating products or liking videos. Victims may subsequently be instructed to pay fees, purchase gift cards, transfer money, deposit cheques or provide banking and identity information.

The university stressed that legitimate employers will not require applicants to make payments or allow their bank accounts to be used.

Users are being encouraged to pause before responding to urgent communications, examine the sender’s full address, check the actual destination of links and independently verify suspicious requests.

The university also warned users never to send passwords by email or approve Duo authentication requests they did not initiate.

Suspicious emails can be reported to University of Iowa ITS, while anyone who has entered credentials, approved an unexpected Duo request or suspects their account has been compromised is being advised to contact IT support immediately.

Browse our latest issue

Intelligent Edu.tech

View Magazine Archive