Watch out for "Administrative Assistant (Remote)" Job Scam

By: Zachary Beese, IT Security Manager
August 18, 2026

Share this Article 

A fraudster sent an email to ISU inboxes that advertises an appealing job opportunity. The first line of the email reads "IOWA STATE UNIVERSITY," making it seem like the university is affiliated with the sender. However, the sender uses a Gmail email address. The job is for an "Administrative Assistant (Remote)" and includes a description of position details, responsibilities and application instructions. 

Target Audience

This scam email targets students who are interested in remote, part-time work.

How It Works

  • Students receive an email advertising a job opportunity for "Administrative Assistant (Remote)." The job appears too good to be true (very little time commitment, high pay).
  • Application instructions within the email contain a link to "Fill out form."  After clicking the link, a form opens which includes fields for banking information. 
  • After submitting the completed "application" form, the fraudster will reach out to offer the fake job. 
  • Because they know you have a legitimate, primary bank, they'll give you a check for mobile deposit. You are prompted to use that money to buy job materials from the fraudster's own website.  
  • What happens if you fall for it: The check the fraudster provided will end up bouncing, meaning there is no actually money behind it. You will be out any funds you spent on job materials from the fraudster's website. The fraudster has pocketed that money.

Red Flags

  • The job responsibilties combined with wage are too good to be true -- roughly $75/hour.
  • A legitimate employee or office at the university will have an @iastate.edu email address rather than @gmail.com.
  • Strict instructions for "mobile deposit only" indicate a check is suspicious and may bounce.
  • You can be assured the job is fradulent when your bank informs you the check didn't clear, and your "new employer" is nowhere to be found.

Security in Action

When people report these scams with the Report Phishing" button, the ITS Security team will verify the scam and remove email from all affected inboxes. Additionally, we will notify all recipients who received the scam about the job scam for awareness.

Phishing email from a Gmail email address advertising a false job opportunity.
Fraudulent job application form that includes fields for banking information

 

 

Beware of Device Code Phishing

By: Zachary Beese, IT Security Manager
August 17, 2026

Share this Article 

Microsoft login screen that says "enter code to allow access"

A fraudulent email recently hit campus inboxes that features a PDF with a harmful link. The PDF itself isn't malicious, but it does contain a link to lure recipients into visiting a malicious website. When the link is clicked, a website opens and shows a "Verification Code." 

The site makes users believe they must input the verification code in order to see or open a shared document. However, if you paste/type the "Verification Code," the attacker is given access to your account with their device. This is especially sneaky, because the attacker never needs your username, password or MFA. It also uses the correct URL at Microsoft for logging in.

Target Audience

This phishing email targets anyone with an ISU email address.

How It Works

  • A PDF attached to an email contains information of interest to the campus community. Sometimes it's more targeted to a small set of individuals.
  • The PDF links to a site with a Shared Document and button to "open" the document. The website also contains a "verification code."
  • Clicking the "open" button redirects to a Microsoft Device Code Registration pop-up, using the real Microsoft login we are all used to seeing. 
  • What happens if you fall for it: If you input the verification code after clicking "open," it grants an attacker access. This means an attacker will be able to access your university account, including email, Workday, Canvas, and any other apps you have access to.

Red Flags

  • The biggest red flag here is the final page that says, "Enter code to allow access." It doesn't mention the document at all, and it warns you not to enter codes from sources you do not trust.
  • A user experiences multiple "hops" to access the referenced Shared Document - from email in Outlook, to a PDF, to a website, then through the "Open" button.
  •  PDFs that only contain a link are suspicious, because why not just send the link?  
  • There is a fake Docusign page. By looking at the URL, you see it's a very obscure domain.

Security in Action

Few devices require device code registration. We have put a block in place for most device code registrations except a few places where they are needed. Exceptions are for devices like our phones, Extron panels and a few other embedded devices. If your devices need device code registration, contact the ITS Security or Identity Services to discuss an exemption to this security control. 

Security Terms

  • Phishing: Any malicious email that typically tries to get you to enter credentials or personal details on a form, or in this case any email that is a lure for fraud (or impersonation).
  • Lure: Anything to entice an individual to take a specific action. Examples include: Details about some sort of misconduct, a threat that adverse action will be taken, or the lure of an easy money job.
Fraudulent site page that says "secured documents shared"
fraudulent Docusign screen with authentication code

Look out for the Zoho Assist "Student Report" Scam

By: Zachary Beese, IT Security Manager
August 3, 2026

Share this Article

A fraudulent email recently seen in campus inboxes claims that "President David Cook has shared a document concerning a student report submitted by a parent or guardian." The message attempts to create a sense of urgency and encourages recipients to download a file that ultimately launches a Zoho Assist remote access session.  Other Names were impersonated in several of the false notifications including the Provost and others.

While Zoho Assist is a legitimate remote support tool, cybercriminals are misrepresenting the software to gain unauthorized access to a computer. If successful, the scam gives an attacker the ability to view your information, install software, capture credentials, or take other actions on your device.

Target Audience

This phishing email primarily targets faculty members teaching summer courses.  However, some of these have made their way to students and staff.

How It Works

  • The email claims a student report requires immediate review and includes links to an attached document and a file labeled "ZA Access My Department." 
  • Recipients are instructed to download the file, open it, and approve a Zoho Assist window by clicking "Next," "I Agree," and other prompts until the installation is complete.
  • The goal is not to share a student report. The goal is to convince the recipient to install software that allows a remote connection to the computer. 
  • What happens if you fall for it: Once access is granted, an attacker may be able to control the device and access sensitive information. IT employees at the university will have to remove the harmful software from your university-owned device.

Red Flags

  • The email uses the name of President David Cook to create a false sense of authority.  Other names including the Provost are sometimes used for the notification.
  • It references a vague "student report" without providing context, case information, or a legitimate university process.
  • The “student report” is outside of Workday, ISU’s student information system of record.
  • The email contains inconsistent wording, such as references to a "statement" rather than a student report.

Meet the Contributors

Zachary Beese helps protect Iowa State University's digital environment as a member of the Information Technology Services (ITS) security team. As Manager of Information Security, he works to safeguard university systems, respond to cybersecurity threats, review security risks and support campuswide efforts to keep information secure. Working on the front lines of cybersecurity incident response, he direct exposure to the fraudulent emails, phishing campaigns and social engineering attacks that target university users.

Rich Tener helps lead Iowa State University's efforts to protect its digital environment as Chief Information Security Officer in Information Technology Services (ITS). He works with campus partners to strengthen cybersecurity practices, manage security risks and guide the university's response to emerging threats. He and members of the ITS Security team help shape the strategies, policies and initiatives that keep university systems and information secure.