Security alert: Compromised Deakin account used in recent email scam
Over the weekend, a compromised Deakin account was used to send thousands of scam emails to students, staff and even external contacts. While the issue was quickly contained, it’s a timely reminder that scams aren’t always easy to spot – and sometimes they come from accounts that look completely legitimate.
Here’s what happened, what to watch out for, and how you can protect yourself.
What happened?
Over one weekend, a cyber scam spread quickly after a Deakin account was compromised. The attacker used that account to send thousands of emails to the Deakin community.
The scam worked in two stages.
First, some people received a fake Microsoft 365 file-sharing email encouraging them to click a link and sign in.

That link led to a fake login page designed to steal passwords.
Once the attacker gained access, they used the account to send a second scam to thousands of recipients offering free high-value items, but with a catch.
Anyone who showed interest were later asked to pay a “shipping fee” using gift cards, vouchers or prepaid cards.
Why this scam was convincing
This wasn’t your typical obvious scam. It worked because it:
- came from a real Deakin account, not a fake address
- offered expensive items for free, lowering people’s guard
- moved the conversation off email (e.g. to phone), making it harder to verify
- introduced payment later, after building trust
- asked for gift card payments – a major red flag in scams.
What to watch out for
Even if an email looks legit, stay alert for:
- unexpected emails – even from Deakin accounts
- messages asking you to open shared files you weren’t expecting
- links that prompt you to sign in using your Deakin credentials
- “too good to be true” offers (especially free tech or expensive items)
- requests for gift cards, vouchers or prepaid payments
- unexpected MFA (multi-factor authentication) prompts.
How to stay safe
Protect yourself with these simple steps:
Don’t
- Click links or open files you weren’t expecting
- Enter your Deakin password after clicking a link in an email
- Approve MFA requests you didn’t initiate
- Send money via gift cards or prepaid vouchers
Do
- Verify unusual requests via a separate, trusted Deakin channel using known contact details
- Report any suspicious emails by using the “Report Message” (phishing) button in Outlook
- Be cautious about offers that seem too good to be true
If you interacted with the scam
Act quickly if you clicked a link, entered your details, replied, or made a payment:
- Change your Deakin password, immediately.
- Check your account security settings by reviewing your sign-in methods and remove anything unfamiliar.
- Report the email using the ‘Report Phishing’ button in Outlook – this helps protect others too.
- Contact the IT Service Desk.
- Check your student details in StudentConnect to ensure nothing has changed unexpectedly.
- Run a malware scan on your device using a free antivirus – especially if you downloaded anything or used a personal device. You can also follow these steps to recover from malware.
Before you click, pause
Scams don’t always come from strangers, they can come from real accounts that have been compromised.
If something feels off – even slightly – pause. Don’t engage and report it straight away.
By staying alert and reporting suspicious activity, you’re not just protecting yourself, you’re helping keep the entire Deakin community safe.

You must be logged in to post a comment.