Watch out for "Administrative Assistant (Remote)" Job Scam
By: Zachary Beese, IT Security Manager
August 18, 2026
A fraudster sent an email to ISU inboxes that advertises an appealing job opportunity. The first line of the email reads "IOWA STATE UNIVERSITY," making it seem like the university is affiliated with the sender. However, the sender uses a Gmail email address. The job is for an "Administrative Assistant (Remote)" and includes a description of position details, responsibilities and application instructions.
Target Audience
This scam email targets students who are interested in remote, part-time work.
How It Works
- Students receive an email advertising a job opportunity for "Administrative Assistant (Remote)." The job appears too good to be true (very little time commitment, high pay).
- Application instructions within the email contain a link to "Fill out form." After clicking the link, a form opens which includes fields for banking information.
- After submitting the completed "application" form, the fraudster will reach out to offer the fake job.
- Because they know you have a legitimate, primary bank, they'll give you a check for mobile deposit. You are prompted to use that money to buy job materials from the fraudster's own website.
- What happens if you fall for it: The check the fraudster provided will end up bouncing, meaning there is no actually money behind it. You will be out any funds you spent on job materials from the fraudster's website. The fraudster has pocketed that money.
Red Flags
- The job responsibilties combined with wage are too good to be true -- roughly $75/hour.
- A legitimate employee or office at the university will have an @iastate.edu email address rather than @gmail.com.
- Strict instructions for "mobile deposit only" indicate a check is suspicious and may bounce.
- You can be assured the job is fradulent when your bank informs you the check didn't clear, and your "new employer" is nowhere to be found.
Security in Action
When people report these scams with the Report Phishing" button, the ITS Security team will verify the scam and remove email from all affected inboxes. Additionally, we will notify all recipients who received the scam about the job scam for awareness.
Beware of Device Code Phishing
By: Zachary Beese, IT Security Manager
August 17, 2026
A fraudulent email recently hit campus inboxes that features a PDF with a harmful link. The PDF itself isn't malicious, but it does contain a link to lure recipients into visiting a malicious website. When the link is clicked, a website opens and shows a "Verification Code."
The site makes users believe they must input the verification code in order to see or open a shared document. However, if you paste/type the "Verification Code," the attacker is given access to your account with their device. This is especially sneaky, because the attacker never needs your username, password or MFA. It also uses the correct URL at Microsoft for logging in.
Target Audience
This phishing email targets anyone with an ISU email address.
How It Works
- A PDF attached to an email contains information of interest to the campus community. Sometimes it's more targeted to a small set of individuals.
- The PDF links to a site with a Shared Document and button to "open" the document. The website also contains a "verification code."
- Clicking the "open" button redirects to a Microsoft Device Code Registration pop-up, using the real Microsoft login we are all used to seeing.
- What happens if you fall for it: If you input the verification code after clicking "open," it grants an attacker access. This means an attacker will be able to access your university account, including email, Workday, Canvas, and any other apps you have access to.
Red Flags
- The biggest red flag here is the final page that says, "Enter code to allow access." It doesn't mention the document at all, and it warns you not to enter codes from sources you do not trust.
- A user experiences multiple "hops" to access the referenced Shared Document - from email in Outlook, to a PDF, to a website, then through the "Open" button.
- PDFs that only contain a link are suspicious, because why not just send the link?
- There is a fake Docusign page. By looking at the URL, you see it's a very obscure domain.
Security in Action
Few devices require device code registration. We have put a block in place for most device code registrations except a few places where they are needed. Exceptions are for devices like our phones, Extron panels and a few other embedded devices. If your devices need device code registration, contact the ITS Security or Identity Services to discuss an exemption to this security control.
Security Terms
- Phishing: Any malicious email that typically tries to get you to enter credentials or personal details on a form, or in this case any email that is a lure for fraud (or impersonation).
- Lure: Anything to entice an individual to take a specific action. Examples include: Details about some sort of misconduct, a threat that adverse action will be taken, or the lure of an easy money job.