Warning: university users’ identities misused to send fraudulent emails
The Cybersecurity Team of Masaryk University is warning about fraudulent emails that misuse the identities of university users in an attempt to obtain money, while also gathering information about the recipient and their work environment.
What do you, as a user, need to know?
In the recorded cases, the attacker misused the identities of Masaryk University users and contacted their international colleagues in their names. Both email communication and communication via WhatsApp were observed, with work contacts in Sweden, Portugal, and Spain among those targeted. In the case of email communication, the message header was modified to make the email appear as though it had been sent by a Masaryk University user. However, the actual sender was an email address controlled by the attacker: editor.in.chief512@gmail.com.
The fraudulent message was designed to resemble ordinary work-related communication. The attacker asked the recipient for help with temporarily arranging a transfer of funds to a third party in Europe, claiming that their own transfer was currently delayed due to an ongoing review. At the same time, the attacker promised to reimburse the full amount the following week, including any fees associated with the transfer. The attacker impersonated a person whom the recipient might know or regard as trustworthy based on previous professional interactions.
The attacker’s primary objective was to persuade the recipient to transfer money. At the same time, any response to the message could also provide the attacker with additional information about the victim and their work environment, such as professional relationships, communication patterns, working procedures, or their willingness to respond to similar requests. This information could subsequently be used in further phishing or other attacks.
Update as of 11 August 2026
So far, the reported cases of fraudulent communication have been observed only within the Faculty of Arts at Masaryk University. If similar cases are identified at other parts of Masaryk University, we will update the information accordingly.
Specific steps:
If you did not click on any links or download any attachments, your account was most likely not compromised, and the attacker merely misused your name and identity based on publicly available information.
However, we generally recommend that users:
- Check the sender’s actual email address, not just the displayed name, which can be easily spoofed. A fraudulent email may use the name of a colleague you know while actually being sent from an unrelated address.
- Do not respond to unusual requests for payment or information without first verifying them. Contact the person concerned through a different communication channel.
- Report suspicious communication to The Cybersecurity Team of Masaryk University. Forward the email or attach its text, including any links, attachments, and email headers.
More information
If you are interested in the context, the terminology, or would like to better understand the reasons behind this warning.
Why did this message reach me, and what have we done to protect users?
To make it easier to recognize trusted senders, you can create a custom category and rule in your email client that marks messages received from specific verified email addresses. If an attacker attempts to impersonate your colleague using a different or similar-looking address, this label will not appear.
You can find the instructions in our guide, Protect yourself from phishing in Outlook: creating a category and setting up a rule.
Conclusion
Be particularly cautious of unusual requests made in the name of your colleagues or acquaintances. Always verify the sender’s actual email address, and if you have any doubts, confirm the request through a different communication channel. Report suspicious communication to The Cybersecurity Team of Masaryk University.
You can always find everything important about cybersecurity at Masaryk University on https://security.muni.cz/en.