Colleges and universities face threats directed at both their people and their operations. Faculty and researchers hold valuable research and intellectual property. IT, identity, and help-desk personnel control access to institutional systems. HR, payroll, finance, and procurement employees administer processes that can be exploited for fraud. Public-facing faculty, administrators, and campus leaders may also face doxxing, harassment, stalking, and physical threats.
In August 2026, the U.S. Department of Justice announced a superseding indictment charging 17 members of the Iran-based Mabna Institute.
According to the allegations, the group conducted a coordinated campaign of cyber intrusions against 144 U.S. universities and 178 universities in other countries. The university spearphishing campaign was allegedly conducted on behalf of Iran’s Islamic Revolutionary Guard Corps.
The indictment alleges that the group targeted more than 100,000 professor accounts and successfully compromised approximately 8,000. The defendants allegedly used stolen credentials to access professor accounts and steal academic journals, theses, dissertations, electronic books, and other research materials, totaling at least 31.5 terabytes of academic data and intellectual property.
The campaign demonstrates the scale at which adversaries can target professors’ identities and accounts as routes to institutional research and intellectual property.
University personnel are being targeted for credential and payroll theft
Higher education personnel are also being targeted by financially motivated actors.
In October 2025, Microsoft Threat Intelligence documented a campaign by Storm-2657 that used phishing to compromise university employee accounts and redirect salary payments.
Beginning in March 2025, Microsoft observed eleven compromised accounts at three universities being used to send phishing emails to nearly 6,000 accounts across 25 universities. Attackers stole credentials and multifactor authentication codes, accessed employee email accounts and Workday profiles, changed payroll information, and created inbox rules to conceal notifications of the changes.
The phishing messages were tailored to higher-education environments. Some referred to illnesses or outbreaks on campus, faculty misconduct reports, compensation and benefits, HR documents, university names, or university presidents.
This campaign shows how attackers can turn a university employee’s identity into both an initial target and an instrument for reaching additional personnel. It also demonstrates why employees in HR, payroll, IT, identity management, and other operational roles warrant protection alongside senior leaders and researchers.
Faculty and other campus personnel face doxxing and harassment
The risks extend beyond institutional systems and financial fraud.
The American Association of University Professors identifies targeted online harassment as a significant threat to faculty and academic freedom. Faculty members have been placed on watchlists, harassed through social media, and subjected to threats based on statements attributed to them, their teaching, or their public commentary.
George Washington University similarly reports that students, faculty, and staff have been doxxed by individuals and organizations. The university defines doxxing as the publication of information such as personal email addresses, phone numbers, and home addresses to intimidate or frighten the target and encourage further harassment.
These incidents illustrate the importance of reducing access to personal contact, location, and family information before it can be used to find and target members of a campus community.
Higher-education institutions recognize data-broker exposure as a cyber and safety risk
Universities recognize that personal information exposed by data brokers and people-search sites creates both cybersecurity and personal-safety risks.
University privacy guidance recommends limiting personal information online, monitoring what is exposed, and opting out of data-broker websites. It places data-broker removal alongside strong, unique passwords, multifactor authentication, and phishing awareness as part of a broader set of protections addressing risks that include identity theft and physical harm.
Additional higher-education guidance recommends removing personal information from data brokers as part of guidance addressing online harassment, stalking, possible identity theft, and harms extending into the physical world.
University research also identifies a direct cyber risk. A UC Irvine investigation of data brokers reported that data-broker sales can give malicious actors access to personal information for phishing, fraud, and identity theft.
Additional documented cases involving the use of data brokers for cyber and physical targeting reinforce these conclusions. Together, the guidance, research, and real-world evidence support treating personal data removal as a practical component of higher-education cybersecurity, privacy, and personal-safety programs.
Protection should reflect the roles being targeted
The higher-education attack surface extends well beyond presidents and other senior executives. Institutions should consider the exposure of personnel whose visibility, access, authority, or research makes them attractive targets, including:
- Faculty and researchers with access to valuable research or intellectual property
- University executives, administrators, trustees, and other public-facing leaders
- IT, security, identity, help-desk, and systems-administration personnel
- HR, payroll, finance, procurement, and other employees who control institutional processes
- Faculty and staff facing elevated risks of doxxing, stalking, harassment, or physical threats
Role-based protection allows an institution to align coverage and spending with actual risk while maintaining broader options for employees who need protection.
Reducing the personal-data attack surface
Removing exposed profiles helps disrupt attacker reconnaissance by limiting the intelligence malicious actors can gather about faculty, researchers, administrators, and staff through commercial data sources.
Optery for Business provides:
- Patented search technology that finds approximately 40–50 more exposed profiles per person on average than other personal data removal services
- Automated removals across more than 640 data-broker sites
- Coverage of more than 1,000 sites when Custom Removals are included
- Before-and-after screenshots documenting exposure and completed removals
- Recurring scans and removals to address new and repopulated profiles
- Centralized administration, reporting, and exposure metrics
- Bulk enrollment and self-service deployment
- SSO and SCIM integration
- Tiered, role-based protection to help institutions align coverage with risk and budget
- SOC 2 Type II attestation
Institutions already using DeleteMe or another personal data removal provider can run a free Optery scan to identify profiles that remain exposed. Optery’s patented search technology finds approximately 40–50 more exposed profiles per person on average than other services, enabling more comprehensive removal of the personal data and more complete protection.
Higher-education organizations can contact the Optery Team to begin a free 30-day Optery for Business trial for a select group of personnel. Book a demo or contact the Optery team at Carahsoft to begin a free 30-day trial for a select group of high-risk personnel.

