Mandiant observed an increase in phishing attacks targeting U.S.-based universities since August 2024.A long-term phishing campaign with shared filenames targeted educational institution users since at least October 2022.These attacks exploit trust within academic institutions during critical academic calendar dates.Three distinct phishing campaigns have emerged to take advantage of these factors.Campaigns involved phishing via Google Forms, scraping university login pages, and redirecting payments.Phishing methods included requests for login credentials, financial information, and urgent responses.Google Forms and website cloning were used in phishing campaigns to obtain sensitive information.Payment redirection attacks involved gaining unauthorized access to redirect funds into attackers' accounts.The impact of a successful payment redirection attack includes financial losses, reputational damage, and operational disruption.Mitigation strategies include MFA, employee training, payment verification protocols, and incident response planning.