惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
月光博客
月光博客
MyScale Blog
MyScale Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
爱范儿
爱范儿
P
Proofpoint News Feed
人人都是产品经理
人人都是产品经理
Last Week in AI
Last Week in AI
罗磊的独立博客
G
Google Developers Blog
Y
Y Combinator Blog
博客园 - 【当耐特】
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
J
Java Code Geeks
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
美团技术团队
宝玉的分享
宝玉的分享
Jina AI
Jina AI
小众软件
小众软件
T
Tailwind CSS Blog
A
About on SuperTechFans

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog A New Ransomware Leader Emerges as June 2026 Attack Volumes Climb Worldwide
How Check Point Email Security Stopped a Student Job Scam...
lizwu@checkpoint.com · 2026-07-10 · via Check Point Blog

A student receives what looks like a routine summer job offer from a trusted school account. The link goes to Google Forms. The email passes authentication. There is no malware, no fake login page, and no strange-looking domain. To the student and to many security tools, it looks harmless. 

But this is where modern phishing succeeds: it borrows trust instead of faking it. In this case, Check Point Research observed more than 3,200 copies of a phishing campaign targeting students with the promise of flexible summer work. The emails were sent from a compromised but legitimate school mailbox and directed recipients to a real Google Forms page rather than an attacker-owned website. 

That is the gap Check Point Email Security is built to close. Instead of relying only on whether a sender is authenticated or a link belongs to a reputable domain, it evaluates the broader context of the message: who sent it, whether the behavior is unusual, what the message is asking the recipient to do, and whether the destination is being used in a suspicious way. 

For attacks like this, that shift matters. The threat was not obvious technical malware. It was intent: recruit students into what appears to be a money mule scheme and collect information that could support future phishing or account compromise. 

Reading the Signals Beneath the Surface 

Check Point Email Security is built to analyze messages before delivery, connect context and behavior, and block threats before users or AI systems can interact with them. In a campaign like this, several signals matter together: 

Sender behavior: Was the school mailbox suddenly sending job offers at unusual volume? A compromised account may pass authentication while still behaving abnormally. 

Message intent: The email promoted work, but the application lacked employer details and asked for information that could be misused. 

  • Hosted form analysis: A Google Forms link does not guarantee the form is safe
  • Financial-risk language: Banking questions before a formal offer can signal money mule recruitment
  • Account compromise: A legitimate sender can still be malicious if the mailbox has been taken over
  • Workspace context: Phishing often moves across email, forms, files, collaboration apps, identities, and SaaS platforms

With those signals in mind, here is how the scam unfolded. 

Anatomy of the Fake Job Offer 

The email invited students to apply for flexible summer work through a “secure” application form. The form collected basic contact details, but two questions stood out: 

  • Financial institution: Legitimate employers rarely ask for banking information before a formal offer. At the application stage, this can signal money mule recruitment
  • Official school email address: Verified educational accounts can support credential harvesting, account takeover, internal impersonation, or future BEC attacks

Figure 1: The email

Figure 2: The job offer

The Problem With “Trusted” Senders 

The scam worked because it looked ordinary: a school account, a Google Forms link, and a simple job application. For students looking for summer work, that was enough to feel credible.  It passed authentication: SPF, DKIM, and DMARC confirmed the message came from a legitimate account, not whether that account was compromised.  It used trusted infrastructure: Google Forms gave the link the reputation of a familiar cloud service.  It avoided obvious payloads: No attachment. No malware. No fake login page. 

When Reputation Isn’t Enough 

Authentication and reputation are useful signals, but they answer narrow questions: did the message come from where it claims, and does the link point to a known service?  In this campaign, both answers looked safe. What they could not show was whether the sender had been compromised or the form was being used for fraud. Modern email security has to evaluate intent, context, and behavior—not just authentication or link reputation. 

When the Inbox Becomes the Entry Point 

Email is no longer just something people read. It is also content that AI assistants and automated workflows can summarize, route, extract from, and act on. That matters in a scam like this because the message was designed to look routine: a job offer, a form, and a trusted sender. Once that kind of message is delivered, it can be treated as legitimate by the people and systems that rely on the inbox as a source of truth. 

Detecting Intent Before Impact 

This student job scam did not rely on fake domains, malware, or obvious red flags. It relied on trust: a real school account, a real Google form, and a plausible message. 

Check Point Email Security is designed for that reality. With AI-native detection, prevention-first inline protection, continuous analysis, and complete email and workspace security, it helps identify malicious intent before sophisticated phishing reaches users, AI assistants, or automated workflows.