VCU Responds to Cyberattacks with "Stop, Verify, Report" Campaign

VCU Launches Security Campaign After Phishing and Hacking Incidents

MEDIUM
August 26, 2026
4m read
PhishingIncident ResponseCyberattack

Impact Scope

People Affected

7,000+ students targeted

Affected Companies

Virginia Commonwealth University (VCU)

Industries Affected

Education

Related Entities

Threat Actors

ShinyHunters

Products & Tech

DuoCanvas

Full Report

Executive Summary

Virginia Commonwealth University (VCU) has launched a new cybersecurity awareness campaign, "Stop, Verify, Report," in response to a recent wave of cyber incidents targeting its students and platforms. The initiative follows a significant phishing campaign in early August that targeted over 7,000 students and an earlier incident in April where the university's Canvas learning platform was defaced. The campaign aims to arm students and faculty with a simple, memorable framework to combat social engineering attacks, reinforcing the idea that cybersecurity is a shared responsibility.


Incident Timeline

  • Late April 2026: The hacking group ShinyHunters reportedly breached a third-party service, causing ransom notes to appear on the Canvas login pages for VCU and other universities.
  • Early August 2026: A large-scale phishing campaign is launched against VCU students. Over 7,000 students receive emails impersonating the "VCU IT Department."
  • Attack Details: The phishing emails created a false sense of urgency, threatening to remove students from their courses unless they immediately provided their login credentials and Duo multi-factor authentication codes.
  • Late August 2026: In response to the incidents, VCU officially launches the "Stop, Verify, Report" awareness campaign.

Response Actions

VCU's response is a multi-departmental effort involving its Enterprise Marketing and Communications, Information Security Office, Student Affairs, and VCU Police. The core of the response is the "Stop, Verify, Report" campaign:

  • Stop: Encourages individuals to pause and think before clicking links or responding to urgent requests for information.
  • Verify: Instructs users to independently confirm the legitimacy of a suspicious message through an official, separate communication channel (e.g., calling the IT help desk using a known number).
  • Report: Guides users to report all suspicious emails to the university's dedicated phishing analysis address, allowing the security team to investigate and block threats.

In addition to the campaign, VCU has also initiated a "Security Heroes" program to recognize and reward community members who proactively report security issues.


Technical Findings

The primary incident driving the campaign was a classic social engineering attack. The attackers leveraged several techniques:

  • Impersonation: Posing as a trusted entity (VCU IT Department).
  • Urgency: Creating a time-sensitive threat (removal from courses) to provoke a quick, emotional reaction.
  • Credential Harvesting: The goal was to steal usernames and passwords.
  • MFA Bypass: Specifically asking for Duo codes indicates the attackers were prepared to immediately use the stolen credentials to bypass multi-factor authentication and gain access to student accounts.

Detection & Response Improvements

The incidents highlight that even with technical controls like MFA in place, attackers are adapting by targeting the human element. VCU's response focuses on strengthening this human firewall.

  • Detection Gaps: The initial phishing emails successfully reached thousands of student inboxes, indicating a need for enhanced email filtering and threat intelligence.
  • Response Playbooks: The coordinated campaign launch shows that the university has a playbook for communicating security issues and educational materials to its user base.
  • User-Sourced Intelligence: The "Report" function is critical, as it turns 7,000+ students into potential sensors for the security team, enabling faster detection and response to new phishing waves.

Lessons Learned

  • Humans are the New Perimeter: As technical defenses improve, attackers are increasingly focusing on social engineering to trick individuals into giving up access.
  • MFA is Not a Silver Bullet: While essential, MFA can be bypassed through real-time phishing attacks where users are tricked into providing their one-time codes.
  • Clear, Simple Communication is Key: The "Stop, Verify, Report" framework is easy to remember and provides actionable guidance, which is more effective than complex technical instructions for a general audience.

Mitigation Recommendations

Based on the incidents, VCU and similar organizations should focus on a defense-in-depth approach that combines technical controls with robust user education.

  • Continuous User Training (M1017): The campaign is a good start, but it should be reinforced with regular, mandatory security awareness training, including phishing simulations, for all students and staff.
  • Enhanced Email Security: Implement advanced email security gateways with capabilities for impersonation detection, malicious link analysis, and sandboxing of attachments.
  • MFA Hardening: Explore the use of phishing-resistant MFA, such as FIDO2 security keys, for high-risk users and systems to mitigate the threat of code-stealing phishing attacks.
  • Incident Communication Plan: Maintain and regularly test a clear communication plan for security incidents to ensure that users receive timely, accurate, and actionable information.

Timeline of Events

1
April 30, 2026
ShinyHunters group attack leads to ransom notes on VCU's Canvas login page.
2
August 1, 2026
A large-scale phishing campaign targets over 7,000 VCU students, attempting to steal credentials and MFA codes.
3
August 26, 2026
VCU formally announces its 'Stop, Verify, Report' security awareness campaign in response to the incidents.
4
August 26, 2026
This article was published

MITRE ATT&CK Mitigations

The 'Stop, Verify, Report' campaign is a direct implementation of this mitigation, aimed at training users to identify and respond to social engineering attempts.

While VCU had MFA, the attack targeted it. This highlights the need for user training on MFA attacks and considering phishing-resistant MFA.

Mapped D3FEND Techniques:

Implementing stronger email filtering to analyze and block malicious links in incoming emails.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

While VCU's campaign focuses on user education, a technical countermeasure is to implement User Behavior Analysis (UBA). UBA systems can baseline normal user activity and detect anomalies indicative of a compromised account, even if the attacker successfully bypassed MFA. For example, a UBA tool could alert on a student account logging in from a new, unusual geographic location shortly after the phishing campaign, or accessing sensitive systems they've never touched before. This provides a crucial layer of post-authentication defense that is not reliant on the user correctly identifying a phishing attempt.

Timeline of Events

1
April 30, 2026

ShinyHunters group attack leads to ransom notes on VCU's Canvas login page.

2
August 1, 2026

A large-scale phishing campaign targets over 7,000 VCU students, attempting to steal credentials and MFA codes.

3
August 26, 2026

VCU formally announces its 'Stop, Verify, Report' security awareness campaign in response to the incidents.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

PhishingSocial EngineeringEducationIncident ResponseSecurity AwarenessMFA

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.