Free Items Scam Hides Behind a Professor’s Email

The message comes from a university address and offers a piano, camera, laptop, or other valuable item for free. A professor is supposedly helping a widow clear out her late husband’s belongings.

There is only one cost: delivery. That small practical detail is where the giveaway turns into a payment scam.

Realistic reconstruction of a compromised university email offering a widow's expensive household items for free except shipping

Overview

The trusted email address is the hook

A student or employee is more likely to open a message that appears to come from a professor. The sender may be a familiar name from the university directory, and the email can pass basic checks because the account itself has been compromised.

In one reported case, a student trusted such an offer and paid €145 for shipping. The item never arrived. The university connection did not protect the transaction because the professor’s identity had been borrowed.

The “free” item creates a believable reason to pay

The scam does not charge for the piano, laptop, camera, or furniture. Instead, it invents a delivery problem: the owner has moved, the item is already with a shipping company, or local pickup is no longer possible.

Paying €145 to receive something worth hundreds or thousands can feel like a bargain. The victim is comparing the shipping fee with the item’s supposed value, not with the possibility that no item exists.

A moving story keeps the victim from asking practical questions

The owner is often a widow, grieving relative, retiring professor, or family moving overseas. The story explains both the generosity and the rush while making aggressive verification feel insensitive.

Common warning signs include:

  • An unsolicited university email offers expensive items at no cost.
  • The owner is unavailable because of grief, relocation, illness, or military service.
  • The conversation moves to a personal email, text message, or WhatsApp.
  • Local pickup is refused even when the recipient lives nearby.
  • A shipping company contacts the victim before the item is inspected.
  • Payment must be made by bank transfer, gift card, cryptocurrency, or cash app.
  • The tracking page is controlled by a little-known or newly created website.
  • Insurance, storage, customs, or release fees appear after the first payment.

A genuine giveaway can involve delivery costs. The difference is that the item, owner, location, and carrier can all be checked independently before anyone pays.

Realistic reconstruction of a fake shipping invoice demanding a €145 SEPA transfer for delivery of free university giveaway items

How the Free Items Scam Works

Step 1: A professor’s account is compromised or copied

The criminal may gain access through phishing, password reuse, or stolen browser sessions. A real university mailbox is valuable because messages sent from it look internal and may pass spam filters.

In simpler versions, the display name is copied while the actual sender uses a lookalike domain or free email account. On a phone, the full address may remain hidden unless the recipient taps it.

Step 2: A generous backstory explains the giveaway

The message says a widow wants her late husband’s possessions to go to someone who will appreciate them. Another version involves a professor retiring, a family moving abroad, or a relative entering assisted living.

The emotional detail makes the offer memorable and answers the obvious question: why would anyone give away something this valuable?

Step 3: The victim chooses an item and moves off university email

A list may include a piano, MacBook, camera, game console, bicycle, or furniture. Different items attract different recipients, allowing one campaign to reach students, staff, and local families.

Replies are redirected to the supposed owner or a private number. This takes the conversation away from university monitoring and lets the scam continue even if the compromised mailbox is secured.

Step 4: Pickup becomes impossible

When the victim asks to collect the item, it has just been placed in storage, moved to another city, or assigned to a shipping company. The owner may say they have already left the country and cannot meet.

This is the moment the physical item stops being testable. Every later proof comes from messages, photographs, invoices, or websites controlled by the same operation.

Step 5: A fake carrier requests the shipping fee

The victim receives a professional-looking invoice showing dimensions, weight, delivery address, insurance, and a tracking number. The “carrier” may be a separate email account operated by the same scammer.

The requested fee is low compared with the item’s claimed value. A bank transfer is often preferred because it can clear quickly and offers less buyer protection than a card purchase.

Step 6: Another charge appears after payment

Once the first fee is paid, the parcel is supposedly held for refundable insurance, storage, customs, an oversized-item permit, or address verification. The scammer knows the victim now has both money and the imagined item at stake.

A fake tracking page may move the parcel from “registered” to “on hold” to make the new demand look like a real logistics event.

Step 7: The accounts disappear and the campaign continues

The victim is blocked when payments stop. Meanwhile, the compromised professor’s mailbox may send the same offer to hundreds of people, or the criminal may switch to another university account.

Because the story uses a real person’s name, angry recipients may contact or blame a professor who was also a victim of the breach.

This Is a Known University Email Pattern

The University of Twente published a warning titled “A free piano? Don’t fall for it!” after messages from compromised accounts offered free goods and demanded shipping costs. The university advised recipients to verify unusual offers and report suspicious messages.

The University of Illinois Chicago has also described the broader giveaway pattern through its cybersecurity awareness program. These campaigns are effective because a genuine university account creates a level of trust that an unknown address would not receive.

The institution named in the email is not necessarily involved in the payment. A compromised mailbox means the message can be technically real while its contents are fraudulent.

That distinction matters when reporting the incident. Send the full message and headers to the university’s security team so it can secure the account and find other recipients. Do not accuse the professor of personally running the scheme without evidence.

How to Check a “Free Item” Before Paying Shipping

Contact the professor through a second route found in the official university directory. A short phone call to the department can confirm whether the offer was sent intentionally. Do not use a new number introduced in the suspicious email.

Ask to inspect the item in person or arrange pickup by someone you trust. If distance makes that impossible, request a live video showing the item, today’s date, and a specific action you choose. A prerecorded clip is easy to reuse.

Reverse-search the photographs. Giveaway scams often copy images from old marketplace listings, auction sites, product pages, or earlier scam campaigns. Exact matches under different locations and owners are a strong warning.

Verify the carrier separately. Type its official address yourself, call a published number, and enter the tracking number there. Do not trust a tracking site reached only through the sender’s link.

Check whether the shipment makes practical sense. Ask where the item is stored, who packed it, how its weight was measured, and whether pickup is possible from the carrier’s depot. Vague answers usually reveal that no real shipment exists.

If payment is still appropriate, use a method with buyer protection and pay the verified carrier directly. Do not send a bank transfer to an unrelated individual because an invoice uses a shipping logo.

Why Fake Tracking Can Look Real

A tracking site does not need access to a shipping network to look convincing. Templates can reproduce progress bars, depot scans, maps, and status messages. The scammer enters the victim’s number and controls every update.

The page often starts with reassuring movement. After the first payment clears, the parcel reaches a invented checkpoint and changes to “insurance required” or “customs hold.” The website is not reporting the problem; it is creating the next demand.

Check the domain carefully. A carrier name placed before or after extra words is not the official company. Search results can also contain sponsored impostor sites, so type the known carrier address rather than choosing the first result.

Call the carrier and ask it to read back the origin, destination, service level, and parcel weight. A fake number may show a page but will not exist in the real carrier’s internal system.

Do not pay from a countdown page. Real logistics problems can be discussed with the carrier through its official support channel after you close the sender’s link.

Company, Address, and Fulfillment Checks

The professor’s name may belong to another victim

A message from a genuine university account proves only that the account sent it. Confirm the offer with the professor or department through a separate channel before assuming the named person wrote the message.

The item’s location should be specific and testable

A real owner knows where the item is, when it was moved, and whether someone can inspect it. Constantly changing cities, storage facilities, and pickup restrictions are not ordinary delivery complications.

The shipper may be the same scammer in a second role

A new email signature and invoice do not create an independent company. Check the carrier’s domain age, address, telephone number, registration, and tracking system outside the conversation. Call a number you find yourself.

A genuine parcel enters a verifiable network

Real tracking numbers work on the carrier’s official site and show events that the carrier can confirm. A page designed only for one victim, with every update leading to another payment, is not evidence that anything was shipped.

What to Do if You Have Fallen Victim to This Scam

  1. Stop all payments. Do not pay insurance, customs, storage, or release fees. A second payment will not make the nonexistent parcel appear.
  2. Contact your bank or payment service immediately. Report an advance-fee scam, provide the recipient details, and ask whether the transfer can be recalled or frozen. For a SEPA payment, ask specifically about a fraud recall.
  3. Preserve the emails and headers. Save the original message, reply chain, item photographs, invoice, tracking site, bank details, phone numbers, and transaction receipt.
  4. Notify the university security team. Send it the evidence through contact information on the official university website. The team may need to lock a compromised mailbox and warn other recipients.
  5. Contact the real professor carefully. Let them know their identity may be in use. Do not post accusations publicly before the account compromise is understood.
  6. Report the fake carrier. If a legitimate shipping brand was copied, notify that company through its official fraud channel. Also report the hosting domain and payment recipient.
  7. Secure accounts if you shared personal data. Change reused passwords, enable multi-factor authentication, and monitor for phishing if you provided an ID, address, phone number, or bank document.
  8. Scan any device that opened a download. The usual version is a payment scam, but if the email delivered a file or unofficial app, use Malwarebytes to check the device.
  9. Block malicious sites where possible. AdGuard can help stop many known scam and advertising domains, although it cannot verify a giveaway or recover a bank transfer.
  10. Report the fraud locally. Use the national fraud-reporting service or police in your country and provide the bank recipient and full email headers.
  11. Reject recovery offers. Fraudsters may return as bank investigators or recovery agents and demand another fee. Work only with your bank and authorities you contact yourself.

Frequently Asked Questions

Can a scam email really come from a professor’s account?

Yes. If the mailbox was compromised, the message can come from the genuine address. Confirm unusual requests through a university directory or department phone number.

Are all free pianos and household giveaways scams?

No. Legitimate giveaways exist, but the item, owner, location, and delivery can be verified independently. Refusal of inspection combined with an upfront shipping transfer is a major warning.

Why do scammers mention a deceased spouse?

The story explains why valuable belongings are being given away and makes the recipient less comfortable asking skeptical questions. It also creates urgency around clearing the items quickly.

Can a SEPA transfer be recalled?

A bank can attempt a fraud recall, but recovery depends on timing and whether funds remain. Contact the bank immediately and provide complete recipient information.

Does a tracking page prove the item was shipped?

No. A fake site can display any status. Verify the number on the carrier’s official website and call the carrier through independently sourced contact details.

Should I blame the professor named in the email?

Not without evidence. The professor may have lost control of the account or had their display name copied. Report the message to university security so it can investigate.

The Bottom Line

The expensive item is not the product in this scam. It is the reason a shipping fee feels small. The only thing actually being delivered is an invoice designed to move money to the scammer.

Before paying to receive any “free” item, verify the sender through the university, inspect the item, and contact the carrier independently. If the owner cannot permit pickup and the shipper cannot confirm the parcel outside a link in the email, keep your money.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Interactive Brokers 2FA Email EXPOSED: Fake Device Enrollment Steals Logins

Next

Zoho Bookings Email Installs Remote Access Malware