TL;DR: Attackers are using compromised university accounts, cloned sign-in pages, and Duo OTP interception to scale account takeover across 40+ organisations and 30+ universities, then hide activity with mailbox rules and lateral phishing, according to Abnormal AI. The programme gap is not MFA alone, but trust, inbox, and behavioural controls that assume institutional email remains benign.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Attackers Steal Duo OTPs to Compromise Higher Ed Accounts”.
Key questions
Q: What breaks when campus phishing comes from a compromised internal account?
A: When a phishing message comes from a trusted campus account, users are more likely to click and some filters are less likely to stop it.
Q: Why do Duo OTPs and similar one-time codes still fail against phishing?
A: They fail when attackers can control the entire login flow and capture both the primary credential and the second factor in sequence.
Q: What are the signs that mailbox rules are being used for account takeover?
A: Watch for new forwarding, hiding or deletion rules appearing right after a suspicious sign-in, especially when they target security alerts, payroll mail or executive communications.
Practitioner guidance
- Harden internal sender trust checks Score messages from inside the organisation when they reference payroll, benefits, awards or other high-response themes.
- Detect and restrict mailbox rule abuse Alert on new forwarding, hiding and redirect rules created shortly after a sign-in from a new device, unfamiliar geolocation or risky session.
- Reduce OTP relay exposure Shorten one-time password validity, enforce phishing-resistant authentication where possible and treat live OTP entry on a suspicious page as a high-risk event rather than a successful second factor.
Bottom line: The campaign shows that campus account takeover can start with a trusted internal sender and end with the victim’s mailbox being turned into the attacker’s platform.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Campus account takeover is now an identity governance problem, not an MFA problem. The campaign works because trusted internal accounts, inbox rules and behavioural context are all part of the attack surface. MFA still matters, but it sits inside a larger trust chain that attackers can manipulate from the sender account through to post-compromise mailbox control. Universities should read this as a warning that identity assurance now includes message provenance and account behaviour, not only authentication events.
A question worth separating out:
Q: How should universities respond when a compromised account starts phishing colleagues?
A: Contain the account, reset credentials and remove malicious mailbox rules before the attacker can use the same identity to reach more staff or students. Then review outbound mail patterns, sign-in history and message themes to determine whether the account has become a second-stage phishing platform.
👉 Read our full editorial: Campus account takeover campaigns are bypassing MFA in higher education