By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Attackers Steal Duo OTPs to Compromise Higher Ed Accounts” (October 1, 2025)

TL;DR: Attackers are using compromised university accounts, cloned sign-in pages, and Duo OTP interception to scale account takeover across 40+ organisations and 30+ universities, then hide activity with mailbox rules and lateral phishing, according to Abnormal AI. The programme gap is not MFA alone, but trust, inbox, and behavioural controls that assume institutional email remains benign.


At a glance

What this is: This is an analysis of a higher education account takeover campaign that bypasses MFA by combining compromised campus accounts, cloned login portals, Duo OTP theft and post-compromise mailbox abuse.

Why it matters: It matters because IAM and security teams in higher education must treat inbox trust, device risk and session behaviour as part of identity control, not just password and MFA enforcement.


Context

Higher education account takeover now rides on institutional trust, not just credential theft. When attackers can send from compromised campus accounts, the usual email boundary weakens and the login flow becomes only one part of the problem. The primary identity issue is not whether MFA exists, but whether the surrounding communication and mailbox controls assume internal email remains benign.

This campaign shows how phishing, OTP capture and post-compromise mailbox abuse combine into one identity event. After the initial lure, the attacker uses the victim’s own account to spread more phishing, suppress alerts and forward financial mail externally. That creates an identity governance problem for universities that spans human users, mail access and cloud account behaviour.


Key questions

Q: What breaks when campus phishing comes from a compromised internal account?

A: When a phishing message comes from a trusted campus account, users are more likely to click and some filters are less likely to stop it. The failure is not just email security. It is the assumption that internal senders are safe by default, which makes sender trust a target for abuse.

Q: Why do Duo OTPs and similar one-time codes still fail against phishing?

A: They fail when attackers can control the entire login flow and capture both the primary credential and the second factor in sequence. A code proves that the user entered a code, not that the session was genuine. Phishing-resistant authentication reduces this gap by binding the authentication event to the real origin and device.

Q: What are the signs that mailbox rules are being used for account takeover?

A: Watch for new forwarding, hiding or deletion rules appearing right after a suspicious sign-in, especially when they target security alerts, payroll mail or executive communications. Those rules often signal that the attacker is trying to suppress warnings and keep access alive after the initial compromise.

Q: How should universities respond when a compromised account starts phishing colleagues?

A: Contain the account, reset credentials and remove malicious mailbox rules before the attacker can use the same identity to reach more staff or students. Then review outbound mail patterns, sign-in history and message themes to determine whether the account has become a second-stage phishing platform.


Technical breakdown

How compromised sender accounts increase phishing success

When an attacker sends phishing from a real university account, the message inherits internal trust, routing familiarity and often better deliverability than an external sender. That reduces suspicion before the victim even reaches the fake login page. In higher education, decentralized IT and broad user populations make this especially effective because recipients are conditioned to accept unusual requests from legitimate campus addresses. The identity control failure here is not just poor email filtering. It is the absence of sender trust validation, mailbox anomaly detection and risk-based treatment of messages that originate from within the organisation’s own identity perimeter.

Practical implication: treat internal senders as a high-risk source when behaviour or content departs from the account’s normal profile.

How Duo OTP interception works in multi-step phishing

The phishing kit does more than steal a password. It collects the username and password on a cloned portal, passes them into the next step and captures the Duo one-time password through an AJAX POST request before redirecting the user to the real university site. That sequence matters because the victim sees a familiar authentication flow and assumes the login succeeded. The defender’s mistake is to treat MFA as a single checkpoint rather than a sequence that can be proxied, relayed and hidden behind a convincing front end. In this pattern, MFA is not broken by brute force. It is bypassed by controlled user interaction and live session theft.

Practical implication: pair MFA with phishing-resistant controls and session risk checks that detect relay-style login flows.

Why mailbox rules become persistence after account takeover

Once the account is compromised, mailbox rules turn a stolen login into durable operational access. Attackers use those rules to suppress warnings, forward payroll messages externally and keep spreading phishing from inside the institution. That converts a single successful phishing event into persistence, concealment and lateral abuse. The mailbox is therefore not just a communications tool but a control plane for identity abuse when its rules can be altered silently. In this campaign, the post-compromise stage is where the business damage expands because the attacker no longer needs repeated phishing success to keep extracting value.

Practical implication: monitor mailbox rule creation as an account-takeover indicator, not as routine user configuration noise.


Threat narrative

Attacker objective: The attacker aims to convert trusted campus email access into scalable account takeover, internal phishing reach and financial exfiltration through mailbox abuse.

  1. Entry occurs when the victim receives a phishing email sent from a compromised university account, increasing trust and click-through likelihood.
  2. Credential access happens on a cloned login portal that captures username, password and Duo one-time passwords through a staged phishing flow.
  3. Escalation follows when the attacker uses the stolen session to take over the account, create mailbox rules and pivot to additional victims inside the institution.
  4. Impact comes from suppressed alerts, lateral phishing and forwarding of payroll-related mail to attacker-controlled addresses for financial exfiltration.
  • Twilio 0ktapus breach 2022: SMS phishing of employees exposed 209 Twilio customers and 1,900 Signal users, part of the 0ktapus campaign against 130+ firms.
  • Mailchimp breach 2022: Attackers socially engineered Mailchimp staff, used a support tool to export 102 customer lists and exposed customer API keys for phishing.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Campus account takeover is now an identity governance problem, not an MFA problem. The campaign works because trusted internal accounts, inbox rules and behavioural context are all part of the attack surface. MFA still matters, but it sits inside a larger trust chain that attackers can manipulate from the sender account through to post-compromise mailbox control. Universities should read this as a warning that identity assurance now includes message provenance and account behaviour, not only authentication events.

Trusted sender abuse is the real force multiplier in this campaign. The first compromise gives attackers a credible internal voice that bypasses normal scepticism and some perimeter controls. That changes the control objective from blocking obvious spam to detecting identity misuse inside legitimate communication channels. For higher education, the practitioner question is not whether email filtering exists, but whether the institution can detect when an authenticated user becomes the phishing infrastructure.

Mailbox rule persistence is the named control gap this campaign exploits. The attacker does not stop at login theft. They turn mailbox controls into concealment, lateral phishing and payroll diversion mechanisms, which means the account itself becomes the pivot point for ongoing abuse. That is a governance failure around post-authentication authority, and it should be treated as an identity lifecycle and monitoring issue, not a simple mail hygiene issue.

Institution-specific phishing at scale is now cheap enough to industrialise. AI-generated lures and compromised senders allow attackers to tailor messages to faculty, payroll and staff themes with little manual overhead. That raises the bar for security awareness programmes: generic warning signs are no longer enough when the language and sender both look plausible. The implication is that detection must focus on behavioural deviation, not just malicious wording.

Higher education needs a campus trust model that assumes internal email can be hostile. Decentralised IT and open communication cultures create an identity environment where attack paths blend into normal workflows. The practical consequence is that universities must govern internal messaging, mailbox rule changes and risky sign-ins as part of one control domain. The institution that still treats internal email as inherently safe is operating on a broken assumption.

What this signals

Trust in internal email is now part of the attack surface. Security teams in higher education need to treat authenticated campus senders as potentially hostile when their behaviour changes, because message provenance and inbox rules can be abused after the first compromise. The control question is no longer whether an email passed filtering, but whether the identity behind it is behaving normally.

The operational signal to watch is the combination of a new sign-in, a mailbox rule change and outbound mail to internal targets. That pattern often marks the point where the campaign shifts from credential theft to persistence and lateral abuse, which is why incident response has to join identity, messaging and endpoint telemetry.

Account takeover in higher education is now a workflow problem. Attacks succeed when the same account that receives payroll, benefits or recognition mail can also be turned into the delivery mechanism for phishing and data diversion. Universities should assume that controls at the inbox and authentication layers must be designed together, not separately.


For practitioners

  • Harden internal sender trust checks Score messages from inside the organisation when they reference payroll, benefits, awards or other high-response themes. Combine sender reputation with behavioural signals such as account age, reply patterns and unusual recipient targeting.
  • Detect and restrict mailbox rule abuse Alert on new forwarding, hiding and redirect rules created shortly after a sign-in from a new device, unfamiliar geolocation or risky session. Review rules that suppress security notices or move finance-related mail out of sight.
  • Reduce OTP relay exposure Shorten one-time password validity, enforce phishing-resistant authentication where possible and treat live OTP entry on a suspicious page as a high-risk event rather than a successful second factor.
  • Monitor for lateral phishing from compromised accounts Correlate sudden increases in outbound mail volume, internal recipient clustering and template reuse with compromised-account investigations. Use those signals to contain accounts before they become a second-stage phishing platform.
  • Align higher education awareness with real attack flow Train staff and faculty on compromised-sender phishing, fake sign-in portals and OTP interception as a single chain. Focus scenarios on payroll, benefits and institutional recognition themes because those are the lures attackers are actually using.

Key takeaways

  • The campaign shows that campus account takeover can start with a trusted internal sender and end with the victim’s mailbox being turned into the attacker’s platform.
  • Abnormal AI reports activity across 40+ compromised organisations and 30+ universities, which shows the pattern is broad enough to demand programme-level attention.
  • The most relevant control failure is not MFA alone but the absence of mailbox-rule monitoring, sender trust checks and behavioural detection after sign-in.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe campaign bypasses MFA through live OTP interception and proxy-style phishing.
NHI-10 — Human Use of NHICompromised campus accounts are used as identity infrastructure for phishing and mailbox abuse.
Recommendation — Apply phishing-resistant authentication and treat proxied login flows as compromised authentication events. Separate user communications from privileged mailbox actions and monitor for identity misuse inside legitimate accounts.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe campaign combines credential theft with internal spread from compromised accounts.
Recommendation — Map the attack path to credential access and lateral movement detections across email and identity telemetry.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsMailbox rules and post-login privileges are the control boundary abused after takeover.
Recommendation — Review and restrict post-authentication entitlements that let users alter forwarding, filtering and delegation behaviour.

Key terms

  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • Mailbox Rule Abuse: Mailbox rule abuse occurs when an attacker creates or changes email rules to redirect, hide, or preserve messages. It is an identity risk because the attacker is using legitimate platform behaviour to maintain visibility and persistence after access, often without triggering obvious authentication alerts.
  • Trusted-sender abuse: A phishing technique that exploits the legitimacy of a known sender, shared mailbox, or familiar collaboration context to increase user trust. In practice, it turns existing identity relationships into delivery infrastructure for credential theft, session hijacking, and follow-on compromise.
  • OTP relay: An attack pattern where a one-time passcode is captured and reused fast enough to complete authentication before it expires. The user still appears to have authenticated normally, but the resulting session belongs to the attacker, which makes detection harder and containment more urgent.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org