Virginia Commonwealth University

08/13/2026 | Press release | Distributed by Public on 08/13/2026 08:31

As cyberscams intensify, VCU offers three simple words for protection

By Jake Burns
VCU Police

On Aug. 4 and 5, a group of cybercriminals emailed 7,000 Virginia Commonwealth University students. The goal: Compromise their email accounts and use them to scam other VCU students, faculty and staff.

Posing as "VCU IT Department," the scammers threatened to kick students out of classes if they did not provide their login information and a code from the Duo Mobile app, which VCU uses for multifactor authentication.

Thanks to quick reporting from users, VCU contained the threat and minimized the number of individuals affected. But the episode was a reflection of how cyberscammers frequently target the VCU community - and how they leverage timing to steal or extort money from victims. Before students even returned for a new year, digital criminals were targeting campus communities, said Dan Han, VCU's chief information security officer in the Technology Services unit.

"Modern scams can look incredibly real. Webpages that mimic VCU login pages and emails that attempt to copy VCU branding are common," he said. "Some of the more advanced scams will even address their victims by name."

A slogan for safety: Pause. Verify. Report.

Han said scammers target victims through multiple formats, including email, text message/phone calls or even legitimate services such as PayPal, DocuSign or a Microsoft login. And if you have clicked, replied, entered your password, shared a Duo code or approved an unexpected request, stop communicating with the sender immediately. Change your VCU password immediately and report what happened to [email protected]. Fast reporting helps protect your account and the rest of the VCU community.

Scammers want their targets to feel rushed, scared, excited or curious, so VCU promotes this simple but effective slogan: Pause. Verify. Report.

Before taking any action that could compromise their online profiles or network, users should do the following:

  • Pause: Don't engage immediately, as the warning signs of a scam often include urgency, threats, secrecy and promises of easy money.
  • Verify: Don't reply directly to the outreach. Use a known VCU website, directory entry or phone number to contact a purported sender.
  • Report: Send suspicious emails, texts and screenshots to [email protected]. Check current alerts at the Phishing Net blog.

Be on the lookout for these

Scammers constantly evolve their approach and the context of their communication, but several types of scams often target students or staff:

  • SMS text scam: A text sender tries to convince a recipient to send a Duo code, typically through impersonation of trusted entities or by extortion or other threats.
  • Job scam: Pretending to be a faculty member or employer, the sender offers students an "assistant job" so they can steal students' money through fraudulent checks.
  • Party invite scam: A legitimate-looking "party invite" via email includes a link that redirects the recipient to download software, which grants remote access to the computer.
  • Help desk call scam: The sender poses as the VCU IT help desk and calls the user to request a Duo code.
  • Login theft scam: The sender emails or texts a recipient with a "login link" to steal the login credentials.

Han said the proliferation of artificial intelligence and generative AI has improved scammer's ability to appear authentic or to spoof contact information.

"We have seen a significant rise in AI adoption by cybercriminals. Not only can they weaponize exploits faster, they can also use AI-enabled adversarial tools to create extremely convincing scams that trick their victims," he said. "In today's world, language and technical expertise are no longer barriers for cybercriminals worldwide."

Multifactor authentication, like VCU's Duo Mobile program, are increasingly targets of cybercriminals. Users should only approve a Duo push for a login they initiated, and they should never share a password or Duo code.

Han added these reminders about Duo:

  • VCU IT will not ask you to text, read or provide a Duo code.
  • Only use Duo when you personally start the login process.
  • An unexpected Duo request means someone may have your password, so change your password right away.
  • Deny unsolicited Duo requests, and report the message to [email protected].

VCU Police play key role

Anyone can fall victim to cyberscammers because they play on the person's emotions, according to Det. Sgt. David Kelly, who leads the investigative unit for VCU Police.

Last academic year, Kelly's team handled about 30 cybercrime cases. The victims included students, faculty and staff, who in some cases had lost more than $10,000 in an incident.

A majority of cases begin on social media and quickly devolve into extortion attempts that involve threats of violence or humiliation. Threat actors often exaggerate or fabricate their access to sensitive or personal information to prompt payment from victims, according to the FBI.

"All too often, VCU students are approached on social media as targets of scams. The most common are job opportunities or requests to use the victim in an art project," Kelly said. "If someone is asking you to cash or deposit a check and send them money back or buy gift cards, this is not legitimate and communication should be ceased immediately."

Tracking down scammers is difficult. Kelly said most are professional operatives who shield their IP address, and even if investigators track down the perpetrator, they often are overseas and beyond VCU Police jurisdiction. But VCU Police is in regular contact with state and federal cybersecurity agencies to track trends and share resources.

VCU community members can stay up to date on the latest phishing trends at the Phishing Net blog.

Subscribe to VCU News

Subscribe to VCU News at newsletter.vcu.edu and receive a selection of stories, videos, photos, news clips and event listings in your inbox.

Virginia Commonwealth University published this content on August 13, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 13, 2026 at 14:31 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]