{"id":407019,"date":"2026-08-29T15:20:01","date_gmt":"2026-08-29T15:20:01","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=407019"},"modified":"2026-08-29T15:20:01","modified_gmt":"2026-08-29T15:20:01","slug":"fake-research-assistant-job-passport-selfies","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-research-assistant-job-passport-selfies\/","title":{"rendered":"Fake Research Assistant Job Collects Passport Selfies"},"content":{"rendered":"<p>A university student receives an offer for remote research work from someone claiming to be a professor. The message reaches them at exactly the moment when experience, income, and a credible academic reference would be especially valuable.<\/p><div id=\"mwtad3430222048\" class=\"mwtadhigh-1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"7453445881\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The \u201chiring\u201d process looks increasingly official until one request reveals what the job was built to collect.<\/p>\n<figure><img fetchpriority=\"high\" decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" width=\"1200\" height=\"675\" loading=\"eager\" alt=\"Realistic reconstruction of a fake remote research assistant email that moves a university student into a text conversation\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/research-assistant-email.webp\"><\/figure>\n<div id=\"mwtad381306769\" class=\"mwtadheader-1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2917133959\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The scam uses academic authority to lower suspicion<\/h3>\n<p>A recent <a href=\"https:\/\/www.reddit.com\/r\/Scams\/comments\/1u49p5e\/us_gave_scammer_a_photo_of_my_passport_and\/\" target=\"_blank\" rel=\"noopener\">student report<\/a> described an unsolicited remote research assistant offer from someone claiming to be a professor. The supposed professor moved the conversation to text and presented the role as an opportunity to gain experience.<\/p><div id=\"mwtad2239067758\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The victim said an .edu address associated with their school appeared in the process and posed as human resources. Academic email domains feel safer than free accounts, but they can be spoofed, compromised, newly created for an affiliate, or used without the professor&#8217;s knowledge.<\/p>\n<p>Students often expect professors to hire assistants informally. That normal campus pattern gives the scam a believable explanation for direct contact, flexible duties, and a short hiring timeline.<\/p>\n<h3>The fraud combines identity theft with a fake-check setup<\/h3>\n<p>The reported applicant completed one verification using a driver&#8217;s permit and then received a separate verification request by message. They submitted a passport image and verification selfies through that second route.<\/p><div id=\"mwtad1446737868\" class=\"mwtadp2 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The supposed employer later sent a check described as reimbursement for office supplies and survey materials. The applicant was told to buy Apple gift cards and send the codes. They recognized the scam before depositing the check or sharing the codes.<\/p>\n<p>This is more than one trick. The operator may obtain document images and a live selfie, test email and phone access, collect payroll-style information, and then try to convert a counterfeit check into real gift-card value.<\/p>\n<h3>Real platforms can be inserted into a fake hiring story<\/h3>\n<p>The reporter said one part of the process used Outlier, a real remote-work platform. That does not establish that Outlier, the university, or any real professor authorized the contact.<\/p><div id=\"mwtad914443576\" class=\"mwtadp3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>A scammer can direct someone to a genuine site, ask them to create their own account, or exploit an existing onboarding flow. The legitimate page becomes a trust bridge while a separate text conversation controls the dangerous steps.<\/p>\n<p>Check the full chain, not one link:<\/p>\n<ul>\n<li>Did the student apply through an official university job board?<\/li>\n<li>Does the professor list the position on a verified department page?<\/li>\n<li>Can the department confirm the role by telephone?<\/li>\n<li>Does the .edu sender exactly match the university domain?<\/li>\n<li>Why did identity verification move to a separate message?<\/li>\n<li>Who owns the verification domain and receives the document?<\/li>\n<li>Is a check being sent before work begins?<\/li>\n<li>Is the applicant asked to buy gift cards or send codes?<\/li>\n<li>Do job duties remain vague while sensitive requests become specific?<\/li>\n<li>Can payroll confirm the employer and tax process?<\/li>\n<\/ul>\n<div id=\"mwtad1410167392\" class=\"mwtadp4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>One verified website cannot authenticate the person who sent the text. Every handoff needs its own verification.<\/p>\n<figure><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" width=\"1200\" height=\"675\" loading=\"lazy\" alt=\"Realistic reconstruction of a fake recruiter chat requesting a passport photo and verification selfie outside the normal hiring platform\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/research-assistant-id-request.webp\"><\/figure>\n<div id=\"mwtad3979884197\" class=\"mwtadheader-2 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9284335404\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Passport and Selfie Request Creates Lasting Risk<\/h2>\n<p>A password can be changed. A passport image and facial verification set cannot be replaced as easily. The combination may be useful for opening or recovering accounts, passing weak know-your-customer checks, creating convincing impersonation attempts, or threatening the victim.<\/p>\n<p>Not every criminal use will succeed. Reputable financial platforms use additional signals, document authenticity checks, device reputation, liveness tests, and fraud monitoring. The victim should still assume the material may be reused.<\/p>\n<div id=\"mwtad752234016\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The separate verification request is especially important. A legitimate employer may use a payroll or background-check provider, but it should explain the provider before sending documents, link to a privacy notice, and keep the process inside an authenticated applicant portal.<\/p>\n<p>A text message asking for direct uploads removes those safeguards. The applicant may not know the legal data controller, retention period, breach contact, or jurisdiction.<\/p>\n<p>Students should never send a passport image simply because a message uses a school name. Call the department using the number on the university&#8217;s official site and ask whether the professor is hiring and which service handles verification.<\/p>\n<p>If a document has already been sent, preserve the URL and message. That evidence may help a verification provider disable an abusive account or help law enforcement connect later misuse to the original collection.<\/p>\n<div id=\"mwtad2451093902\" class=\"mwtadheader-3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5345090394\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Fake Research Assistant Job Scam Works<\/h2>\n<h3>Step 1: A professor offers a desirable remote role<\/h3>\n<p>The message promises flexible research work, useful experience, and professional connection. It may mention the student&#8217;s department, school, or academic interests to appear targeted.<\/p>\n<p>The offer can arrive through email, text, a compromised campus account, or a job platform. A real professor&#8217;s name may be copied from a faculty directory.<\/p>\n<h3>Step 2: The conversation moves to text<\/h3>\n<p>Texting feels normal and fast, but it separates the exchange from university systems that might preserve warnings, block attachments, or reveal the sender&#8217;s real domain.<\/p>\n<p>The \u201cprofessor\u201d can claim to be traveling, in a meeting, or too busy for a video call. Urgency becomes a substitute for an interview.<\/p>\n<h3>Step 3: The applicant receives an instant acceptance<\/h3>\n<p>A brief questionnaire replaces a competitive hiring process. The scammer may say the student&#8217;s profile was recommended or that the project begins immediately.<\/p>\n<p>Fast acceptance creates emotional commitment. The victim begins to think like an employee and treats unusual requests as tasks from a supervisor.<\/p>\n<h3>Step 4: Verification harvests valuable identity data<\/h3>\n<p>The applicant is told to upload a driver&#8217;s license, passport, selfie, tax identifier, bank details, or direct-deposit form. A professional-looking page may display a secure lock icon and privacy language.<\/p>\n<p>The operator can also use a genuine platform for part of the flow, then request a \u201csecond verification\u201d outside it. That extra step should never be treated as routine without confirmation.<\/p>\n<h3>Step 5: A reimbursement check appears<\/h3>\n<p>The employer claims the student needs a laptop, printer, survey supplies, software, gift cards, or participant incentives. Instead of buying the materials directly, the employer sends a check for the applicant to deposit.<\/p>\n<p>Banks may make part of a deposit available before discovering that a check is counterfeit. The visible balance is provisional, not proof that the check cleared.<\/p>\n<h3>Step 6: Real money leaves through gift cards<\/h3>\n<p>The applicant is instructed to purchase Apple or other gift cards and send the codes. Once the code is shared, the criminal can redeem or resell the value without possessing the physical card.<\/p>\n<p>The FTC states that honest employers do not send checks and direct recruits to buy gift cards. This request is not an eccentric research task; it is the extraction stage.<\/p>\n<h3>Step 7: The check fails after the codes are gone<\/h3>\n<p>The bank reverses the counterfeit deposit, leaving the account holder responsible for the amount spent. The fake professor stops responding or claims another payment is needed to correct payroll.<\/p>\n<p>The identity documents remain exposed even if no check was deposited, so stopping the money transfer does not end the recovery work.<\/p>\n<div id=\"mwtad1229191505\" class=\"mwtadheader-4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the .Edu Address Does Not Settle Authenticity<\/h2>\n<p>Universities manage thousands of students, staff members, alumni, contractors, departments, mailing lists, and cloud accounts. A message can originate from an account that was compromised through phishing or weak password reuse.<\/p>\n<p>The visible From line can also differ from the technical sender. Email authentication results, reply-to address, return path, and link destination may reveal that the message did not travel through the expected university infrastructure.<\/p>\n<p>Even a technically genuine account can be misused. A compromised mailbox may contain real signatures, previous conversations, department templates, and contact lists, making the scam unusually convincing.<\/p>\n<p>Do not reply to ask whether the email is real. If the account is compromised, the criminal receives the question. Start a new call to the department or a new message to an address copied from the official faculty directory.<\/p>\n<p>Verify the job itself. A professor should be able to describe the project, funding source, supervisor, hours, deliverables, hiring classification, and university payroll path.<\/p>\n<p>If human resources supposedly contacted you, call the university&#8217;s central HR number. Ask whether the sender works there and whether student employees are ever instructed to purchase gift cards.<\/p>\n<div id=\"mwtad2079163954\" class=\"mwtadheader-6-2 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2830607691\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Identity and Payment Warning Signs<\/h2>\n<ul>\n<li>You never applied for the role.<\/li>\n<li>A professor immediately moves the conversation to text.<\/li>\n<li>There is no live interview or project discussion.<\/li>\n<li>You are hired before references or availability are checked.<\/li>\n<li>Identity documents are requested through a separate link.<\/li>\n<li>The verification page lacks a clear privacy notice.<\/li>\n<li>A passport and selfie are requested before a contract.<\/li>\n<li>The employer sends a check for equipment or supplies.<\/li>\n<li>You are told to buy gift cards and share the codes.<\/li>\n<li>The recruiter refuses a call through the department.<\/li>\n<li>The reply-to address differs from the visible sender.<\/li>\n<li>Urgency is used to prevent questions.<\/li>\n<\/ul>\n<p>The <a href=\"https:\/\/consumer.ftc.gov\/consumer-alerts\/2023\/12\/how-spot-latest-job-scams\" target=\"_blank\" rel=\"noopener\">FTC&#8217;s job-scam guidance<\/a> specifically warns that fake recruiters ask for driver&#8217;s-license, Social Security, and bank information before providing meaningful job details.<\/p>\n<p>MalwareTips explains a similar employer-impersonation pattern in the <a href=\"https:\/\/malwaretips.com\/blogs\/indeed-recruitment-text-scam\/\">Indeed recruitment text scam<\/a>.<\/p>\n<div id=\"mwtad2566412471\" class=\"mwtadheader-6 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3648031192\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>A Practical Plan for Passport and Selfie Exposure<\/h2>\n<p>Start by writing down exactly what was sent. Record the document type, visible fields, front or back image, selfie format, verification link, date, recipient, and any account created during the process.<\/p>\n<p>Preserve the upload confirmation and full URL. Do not revisit the page to test it, because a return visit can expose new device information or trigger another request.<\/p>\n<p>Contact the real verification provider through its official support page. Ask whether the session identifier belongs to its service, which customer created it, and whether the data can be restricted or deleted.<\/p>\n<p>Notify the passport issuer that a digital copy was disclosed to a suspected fraudster. Ask what notation, monitoring, or replacement process applies to a copied document that remains physically in your possession.<\/p>\n<p>Freeze credit and obtain current reports. A freeze reduces the chance that a new creditor will open an account, while reports can show inquiries or accounts that appeared before the freeze.<\/p>\n<p>Create alerts on bank, email, mobile, and payment accounts. Pay attention to password resets, new devices, account-recovery messages, SIM changes, and verification codes you did not request.<\/p>\n<p>Secure the email account used for the application. Remove unknown forwarding rules and connected apps, replace reused passwords, and save recovery codes somewhere offline.<\/p>\n<p>Tell close contacts that convincing messages may use your name, school, photo, or academic role. A short warning can stop an impersonator from obtaining money or more identity documents.<\/p>\n<p>Do not send a second selfie to \u201ccancel\u201d the first verification. A scammer may claim that another pose, video, or document is required to close the file.<\/p>\n<p>Expect follow-up calls that mention the job, check, or university. Detailed knowledge does not prove the caller is helping; it may prove they have the original scam records.<\/p>\n<p>Keep a dated incident log. If misuse appears months later, the log connects the new event with the original exposure and makes reports to banks and authorities more precise.<\/p>\n<p>Identity recovery is a process, not a single password change. Review the plan after one week, one month, and whenever a new alert appears.<\/p>\n<p>Check government-benefit and tax accounts where applicable. A complete identity package can be used beyond ordinary credit applications, so secure official online accounts before an unfamiliar recovery request arrives.<\/p>\n<p>Review payment-app profiles connected to the exposed phone number or email. Remove public search settings where possible and confirm that no new cards, banks, or devices were added.<\/p>\n<p>Consider replacing the email used for sensitive applications if it becomes a persistent target. Keep the old account secured and monitored rather than deleting evidence or losing access to alerts.<\/p>\n<p>Ask the university whether other students received the same offer. A campus-wide warning can stop new uploads and may help administrators identify the compromised account or repeated wording.<\/p>\n<p>Do not blame yourself for responding to a convincing academic offer. Focus on containment, documentation, and quick reporting. Shame delays the steps that make later misuse easier to challenge.<\/p>\n<p>Keep copies of every report number and support reply. If an account later appears, those records show that the document exposure was reported before the fraudulent application.<\/p>\n<p>Review the situation again after tax season and the next academic term, when stolen student identities may be reused for new payroll, grant, or tuition stories.<\/p>\n<div id=\"mwtad183238872\" class=\"mwtadheader-7 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>Confirm the professor and department<\/h3>\n<p>Find the professor on the official university directory and call the department using the published switchboard. Ask about the exact project and role without using contact details from the offer.<\/p>\n<p>A matching name is not enough because faculty identities are public.<\/p>\n<h3>Trace the .Edu message independently<\/h3>\n<p>Check the complete domain, reply-to address, and message headers. Forward suspicious mail to the university security team and ask whether the sending account was compromised.<\/p>\n<p>Do not continue verification through the original thread.<\/p>\n<h3>Verify every onboarding provider<\/h3>\n<p>A legitimate platform used during one step does not authorize a second form sent by text. Open the real platform independently and contact its support if your identity was submitted through a questionable invitation.<\/p>\n<p>Ask who controls and retains the passport and selfie data.<\/p>\n<h3>Define what the check and supplies fulfill<\/h3>\n<p>A real university can purchase equipment through approved vendors, issue documented reimbursements after expenses, or use established payroll processes. It does not need a student to convert a check into gift-card codes.<\/p>\n<p>Treat that instruction as proof to stop.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Stop responding.<\/strong> Do not deposit the check, send gift-card codes, or complete another verification.<\/li>\n<li><strong>Contact the university.<\/strong> Notify campus security, the impersonated professor, department administration, and the email-security team.<\/li>\n<li><strong>Preserve evidence.<\/strong> Save the original email with headers, text messages, URLs, uploaded filenames, check image, and gift-card receipts.<\/li>\n<li><strong>Contact the verification platform.<\/strong> Ask it to preserve logs, restrict the abusive account, and explain where the document data went.<\/li>\n<li><strong>Report passport exposure.<\/strong> Contact the issuing authority for guidance; do not assume replacement is always required without asking.<\/li>\n<li><strong>Create an identity-theft plan.<\/strong> Use <a href=\"https:\/\/www.identitytheft.gov\/\" target=\"_blank\" rel=\"noopener\">IdentityTheft.gov<\/a> and document every exposed identifier.<\/li>\n<li><strong>Freeze credit.<\/strong> Contact Equifax, Experian, and TransUnion, then review existing reports for unfamiliar accounts.<\/li>\n<li><strong>Secure email and phone accounts.<\/strong> Change passwords, enable strong multifactor authentication, and add a carrier account PIN.<\/li>\n<li><strong>Contact the bank.<\/strong> If the check was deposited, tell the fraud department immediately and do not spend the provisional balance.<\/li>\n<li><strong>Contact the gift-card issuer.<\/strong> If codes were shared, report them with receipts as quickly as possible.<\/li>\n<li><strong>Run Malwarebytes.<\/strong> Scan any device used to open attachments or install interview and verification software.<\/li>\n<li><strong>Use AdGuard as a supporting layer.<\/strong> It can block many malicious links, but it cannot retract identity documents already uploaded or authenticate a professor.<\/li>\n<li><strong>Report the fraud.<\/strong> File with <a href=\"https:\/\/reportfraud.ftc.gov\/\" target=\"_blank\" rel=\"noopener\">ReportFraud.ftc.gov<\/a> and <a href=\"https:\/\/www.ic3.gov\/\" target=\"_blank\" rel=\"noopener\">IC3.gov<\/a>.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Can a scammer misuse a passport photo and selfie?<\/h3>\n<p>Yes. The material can support impersonation, account applications, recovery attempts, or further targeted scams, although reputable services use additional checks that may stop misuse.<\/p>\n<h3>Should I replace my passport immediately?<\/h3>\n<p>Contact the passport issuer and describe exactly what was exposed. Replacement rules and the effect of reporting a document vary, so follow the authority&#8217;s current guidance.<\/p>\n<h3>Does an .Edu email prove the professor sent it?<\/h3>\n<p>No. The address can be spoofed, compromised, or misused. Confirm through the department using a new channel found on the official university website.<\/p>\n<h3>What if I never deposited the check?<\/h3>\n<p>You avoided the fake-check loss, but identity exposure may remain. Preserve evidence, contact the verification provider, freeze credit where appropriate, and monitor accounts.<\/p>\n<h3>Is Outlier responsible for the scam?<\/h3>\n<p>The report does not establish that the real platform authorized the recruiter. A legitimate service can be inserted into a false story. Contact its official support about any account created through the approach.<\/p>\n<h3>Can gift-card codes be recovered?<\/h3>\n<p>Sometimes an issuer can freeze unredeemed value if contacted quickly. Keep the cards and receipts, call the number on the card or official site, and report the codes as stolen.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The fake research assistant job does not rely on one obviously fraudulent page. It combines academic authority, a possible .edu account, a real platform, identity verification, and a reimbursement story so that every step lends credibility to the next.<\/p>\n<p>The gift-card request exposes the scheme, but the passport and selfie may be the longer-lasting loss. Verify professors and hiring departments outside the original conversation, and never let an urgent opportunity move identity checks into an unverified text link.<\/p>\n<div id=\"mwtad2803591395\" class=\"mwtadfinal mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3077074880\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A university student receives an offer for remote research work from someone claiming to be a professor. The message reaches them at exactly the moment when experience, income, and a credible academic reference would be &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake Research Assistant Job Collects Passport Selfies\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-research-assistant-job-passport-selfies\/#more-407019\" aria-label=\"Read more about Fake Research Assistant Job Collects Passport Selfies\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":407017,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-407019","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/407019","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=407019"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/407019\/revisions"}],"predecessor-version":[{"id":407258,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/407019\/revisions\/407258"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/407017"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=407019"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=407019"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=407019"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}