College Student Scams Explained: Financial Aid, Housing, and Jobs
Fraudsters don't fabricate authority from scratch. They borrow it from your campus. Here's how that works, and how to recognize it before the damage is done.
Picture the first week of the semester. A student gets an email warning they've been dropped from a required class. They've never seen that notification before they don't yet know what a real one looks like. They click, fill out a form, approve a login prompt, and within minutes their financial aid disbursement has been redirected. The attacker didn't need technical sophistication. They just needed to look like the university.
That is the entire strategy behind the most effective college student scams right now. The lures that catch students most reliably are disguised as familiar institutional processes: dropped-class notices, aid disbursements, rental listings, job offers from campus recruiters. What makes this particularly effective against first-year students is simple they haven't yet learned what normal looks like. They don't know whether a financial aid email arrives via a portal link or a direct form. They're managing unfamiliar systems under real deadline pressure. Scammers build around exactly that.
The threat is not hypothetical. Phishing attacks rose 13.8% in early 2026, according to Anti-Phishing Working Group data cited by Great Basin College. Active campaigns targeting student financial aid accounts were confirmed at both UC Irvine last December and UC Santa Cruz weeks into January.
Every scam covered here runs the same sequence: an unfamiliar process, borrowed institutional authority, manufactured urgency, and an irreversible action. The surface changes an email subject line, a rental listing, a threat call. The engine doesn't.
Before getting into specific forms these scams take, one baseline is worth fixing in mind. Real financial aid offices don't ask for passwords or bank credentials through email links. Federal law prohibits charging for FAFSA assistance, so any offer to expedite aid for a fee is illegal, as Great Basin College notes. As for campus police: UCR's department confirmed, after a documented spoofing incident last spring, that UCRPD does not demand payment over the phone, does not accept money by any remote method, and has no role in immigration enforcement. That's a useful model for evaluating similar calls at any campus. What every variant below is designed to impersonate is this baseline of normal.
Financial aid phishing scams: why they lead and how they unfold
Video of the Day
Financial aid sits at the intersection of real money, unfamiliar processes, and hard deadlines. Most incoming students have no mental model for what a legitimate aid notification looks like. That gap is the target.
The most documented attack starts with an alarming subject line: dropped from class, grade issue, schedule change. These exact lures appeared in active campaigns at both UCI last December and UC Santa Cruz weeks into the new year. The email links to a form often hosted on legitimate platforms like Google Forms or Microsoft Forms, routed through URL shorteners to obscure the destination requesting a password alongside name, date of birth, and phone number. UCI confirmed this attack sequence in detail, noting that the university never requests passwords through email links or online forms.
What happens next is the critical moment. Immediately after submitting the form, an MFA push notification arrives on the student's phone. They often misread it as a routine follow-up to the form they just filled out. Approving it hands the attacker access to email, the student portal, and direct deposit settings. A prompt that arrives without the student initiating a login means someone else is attempting to get in. UCI was unequivocal: never approve an authentication request you didn't personally trigger moments before.
A second variant targets Federal Student Aid credentials directly. Scammers pose as FAFSA expeditors promising faster processing or better results. Once a student hands over their FSA login, the attacker locks them out changing the recovery email, password, and phone number then submits fraudulent applications to collect refunds. The student's full legal name, date of birth, and Social Security number are captured in the process, extending the damage well past the immediate loss, as Great Basin College documented. Legitimate FAFSA help is available through campus financial aid offices and at studentaid.gov at no cost.
A third variant is structurally simpler. An unsolicited text or email announces the student has won a scholarship they never applied for. To receive the funds, they must first pay a release fee. Great Basin College notes that fraudsters specifically demand untraceable payment methods gift cards, wire transfers, cryptocurrency because recovery is nearly impossible once the money moves. The rule has no exceptions: no legitimate scholarship organization requires a fee to release funds.
If an account has been compromised: Change the university account password through the official portal immediately. Log into the student financial portal directly and verify direct deposit settings. Contact campus IT security and financial services. If FSA credentials were shared, report to Federal Student Aid at studentaid.gov right away UCI and Great Basin College both emphasize that speed limits the window for fraudulent disbursements. Preserve every message and form link. UC Santa Cruz directs suspicious emails to [email protected].
Video of the Day
The same pattern runs housing and job scams
Housing fraud and fake job offers aren't separate phenomena from the aid scams above. They borrow the same four-part sequence and tend to strike at the same moment: a student navigating an unfamiliar process with real money on the line. An unfamiliar platform. A landlord or employer claiming authority. Urgency to act before the opportunity disappears. An irreversible payment at the end. Recognizing the engine matters more than memorizing every variant.
A rental listing appears on Craigslist or Facebook Marketplace, often built from photos of a real property. The "landlord" is unavailable to show the unit in person always a convenient story and urgency is manufactured: another interested party, a price that won't hold. Deposits are requested before the student has seen the property, via wire transfer, Venmo, Zelle, Cash App, or cash. JMU's Off-Campus Life office flagged these exact patterns earlier this year, noting that rental scams spike when housing demand peaks end of the school year and end of summer precisely when students are searching for their first off-campus place.
One specific variant worth knowing: a "landlord" sends a check for more than the agreed deposit and asks the student to send back the difference. The check bounces days later. The student's own money is already gone. The same deposit-and-forward structure shows up in fake job scams. In both cases, the scam depends on getting the student to move their own money before the fake payment is discovered. That payment direction is always the tell.
JMU also notes that its Off-Campus Life office can help verify listings and provide referrals. Starting there rather than a general marketplace listing is a meaningful filter.
Fake job offers run two patterns. In the upfront-payment version, a listing or unsolicited recruiter text eventually asks for payment covering a starter kit, training materials, or certifications. The FTC is blunt: anyone who asks a person to pay to get a job is a scammer. In the check-forwarding version, a message appearing to come from a professor or campus office offers flexible part-time work. The "employer" sends a check larger than the agreed amount, asks the student to deposit it, then instructs them to forward the excess. The check bounces days later; the student's funds are gone. The borrowed authority a professor's name, a recognizable campus office is what makes this variant particularly effective with students who haven't yet built the instinct to verify independently.
Treat unsolicited job texts as suspicious. Legitimate campus employment is typically posted through official university career portals or student employment offices, not delivered to a phone out of nowhere, as the FTC has noted.
If you've already paid or responded: Contact the bank or payment app immediately. Preserve all messages and listing screenshots. Report housing fraud to local law enforcement and the platform where the listing appeared. Report job scams to the FTC at ReportFraud.ftc.gov.
When the threat call comes: authority impersonation by phone
Phone-based impersonation operates on fear rather than opportunity, which makes it structurally distinct from the examples above. The target isn't drawn toward something attractive. They're pushed toward payment by a threat. Same engine, different emotional lever.
Last spring, someone spoofed UC Riverside's campus police non-emergency number and called a community member demanding immediate payment, threatening deportation if the money wasn't sent. The call appeared to come from a legitimate campus department number, made possible through widely available spoofing tools. UCR's campus police stated plainly that no technical solution currently exists to fully prevent this kind of phone number manipulation. The response has to be procedural.
UCR confirmed that UCRPD does not demand payment over the phone, does not accept money by any remote method, and has no role in immigration enforcement. The deportation threat is engineered specifically to target international students by weaponizing a real anxiety. When a call does that, the threat itself is the tell.
The response is one step: hang up. Find the department's number on the university's official website not from the caller, not from a callback number they provide. Dial it directly. UCR was explicit: do not accept a transfer from the original call. Any contact information the caller provides leads back to the caller.
If money was sent: Contact the payment provider immediately and file a report with local law enforcement. Document the time, number, and what was said.
How to avoid scams in college: four habits that break the pattern
Each habit below targets a specific point in the attack sequence. Students who recognize the structure unfamiliar process, borrowed authority, urgency, irreversible action will find these feel less like arbitrary rules and more like obvious responses.
1. Go straight to the portal; skip the link.
For account, class, and aid notices, the safest move is to log in through the official portal rather than follow any link in the message. If the message names a problem but you can't find that problem after logging in directly, treat the message as suspect. This was the primary guidance from both UCI and UC Santa Cruz after their documented campaigns. The same logic applies to QR codes, which are just links in a different format. QR-based phishing surged 146% in a single quarter earlier this year, rising from 7.6 million incidents in January to 18.7 million by March, according to Great Basin College citing APWG data. The link or code in the message is the attack surface. The portal is not.
2. Money should not move outward before it moves inward.
Any request for payment before a benefit is delivered to release aid, to secure a rental before viewing, to receive job onboarding materials is a structural red flag. Great Basin College confirms that no legitimate scholarship or grant organization charges a fee to release funds. The FTC says the same about employers. When the requested payment method is a gift card, wire transfer, cryptocurrency, or peer-to-peer app, the irreversibility isn't incidental it's the point, as JMU notes.
3. Treat an unsolicited MFA prompt as a break-in already in progress.
An unexpected authentication push means someone else just entered a password and is waiting for approval. Approving it completes the attack. UCI stated this without qualification after its documented campaign. MFA protects an account only when the account holder refuses every prompt they didn't personally trigger.
4. Verify through the institution, not through whoever contacted you.
This habit covers different ground than the portal rule above. The portal habit applies to digital notifications about accounts and classes. This one applies to any person or office that initiates contact by email, phone, or text. When a message or call creates urgency or demands action, end contact and look up the relevant office independently through the university website. The FTC gives the same guidance for suspicious job contacts: confirm directly with the supposed professor or office using contact information found independently, not the details in the message. UCR applied the same principle to phone calls: hang up, dial the department's listed number, don't accept a transfer. Any contact information the caller or sender provides leads back to them.
What institutions are doing, and where the limits are
Schools aren't standing still. The FAFSA has been updated with real-time fraud detection tools to flag suspicious applications, and more institutions are now requiring identity verification before finalizing aid packages, Great Basin College reported this past June. Students who hit extra verification steps before aid is released are seeing the system working as intended, not encountering unnecessary bureaucracy. That friction can be frustrating particularly for first-generation applicants navigating the aid process for the first time but it is preferable to the alternative.
Phone number spoofing has no complete technical fix, as UCR stated plainly. Scams and impersonation schemes account for nearly 44% of all threats people face, according to Great Basin College a share that reflects precisely how reliably social engineering sidesteps technical controls. Universities are target-rich environments full of people managing unfamiliar systems under deadline pressure for the first time. Institutional controls reduce exposure. They don't replace judgment.
The specific lures will keep evolving. The engine underneath won't. When a message arrives uninvited, claims campus authority, demands quick action, and wants something irreversible at the end stop. Close the message. Find the relevant office through the institution's official website and reach out directly. That path is always available. The link in the message is not required.