Over 70 Domains Used in Months-Long Phishing Spree Against US Universities

A new report from security firm Infoblox reveals that at least 18 American universities have been hit by a prolonged, coordinated phishing attack over a period of many months.

According to Infoblox’s blog post, shared with Hackread.com, this campaign ran from April to November 2025 and aimed to steal student and staff account details, even when Multi-Factor Authentication (MFA) was turned on.

Infoblox’s report also revealed that the campaign operators took steps to hide their tracks, such as changing the attack links often and using services like Cloudflare to mask where their servers were located. However, an initial tip from a security professional at one of the targeted institutions helped Infoblox begin an investigation.

Click here to read the full article

Article posted by: .

GÉANT does not necessarily endorse any opinion, real or implied, expressed by the poster.

All brand, company and product names are trademarks of their respective owners.
Skip to content