According to Proofpoint on 7 December 2021, COVID- and Omicron-themed credential phishing hit North American universities starting in October 2021. Lures used URLs and HTM attachments to spoofed university or Office 365 login pages. Some campaigns also spoofed Duo MFA pages and stole SMS one-time passcodes so attackers could complete the second factor after username and password theft. Compromised campus mailboxes then sent the same class of messages to other universities. Named targets in the reporting include the University of Central Missouri, Vanderbilt University, Arkansas State University, Purdue University, Auburn University, West Virginia University, and the University of Wisconsin-Oshkosh. Proofpoint did not name a known actor. Public reporting does not establish per-organization account volumes or the ultimate campaign objective.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did the Proofpoint university campaigns bypass MFA?
The Proofpoint-tracked university campaigns bypassed MFA by harvesting SMS one-time passcodes on spoofed Duo pages after capturing usernames and passwords on fake campus or Office 365 login pages. According to Proofpoint Threat Insight (Selena Larson and Jake G, 7 December 2021), "In some campaigns, threat actors attempted to steal multifactor authentication (MFA) credentials, spoofing MFA providers such as Duo." Proofpoint also stated that stealing MFA tokens lets an attacker bypass the second layer once they already know the username and password. Public reporting does not establish reverse-proxy session-cookie theft as the primary steal; the documented credential-phase win was password plus SMS OTP on spoofed pages.
Was Duo broken, or was SMS OTP the weak link?
Duo was not reported as a vendor breach in this campaign. The weak link was SMS OTP treated as transferable proof on pages that only looked like Duo or the campus portal. Users typed a live SMS code into an attacker-controlled form, so the real second factor never bound to a legitimate university or Office 365 session. Any MFA that can be read aloud, typed, or relayed fails the same way. A fix that removes transferable OTP and push factors at login exists; the companion post covers that prevention path.
Why did compromised university mailboxes matter?
Compromised university mailboxes mattered because they turned one successful password-plus-OTP harvest into the next wave’s trusted sender. According to Proofpoint, it is likely the actors stole credentials from universities and used those mailboxes to send the same COVID-themed threats to other universities. Peer IT and faculty are more likely to open mail that appears to come from another campus domain. Stopping the initial SMS OTP harvest shrinks the pool of mailboxes available to relay; it does not by itself detect abuse of a mailbox already taken.
Which schools did Proofpoint and press reporting name?
Proofpoint’s campaign write-up and related press naming cover a multi-university wave, not a single-org incident-response report. Named targets include the University of Central Missouri, Vanderbilt University, Arkansas State University, Purdue University, Auburn University, West Virginia University, and the University of Wisconsin-Oshkosh. Proofpoint described thousands of messages aimed at dozens of North American universities. Public reporting does not establish how many accounts fell at each school.
Was this one breach or an ongoing campaign?
This was an ongoing campaign, not one isolated university breach. Proofpoint observed consistent COVID-themed credential theft against North American universities from October 2021, then a pivot to Omicron-themed lures after the variant announcement in late November 2021. Delivery mixed actor-controlled domains (patterns such as sso[.]ucmo[.]edu[.]boring[.]cf and sso2[.]astate[.]edu[.]boring[.]cf) with capture pages on compromised WordPress sites for attachment-based runs. Proofpoint did not attribute a known threat group, and public reporting does not establish the ultimate objective.