
Back-to-school season brings a flood of messages about school fees, registration forms, parent portals, timetables and student finance. That also creates opportunities for back-to-school scams that impersonate schools, teachers, universities and student services to steal money, login credentials or personal information.
Here are the scams parents and students should watch for and how to tell if a school-related message is legitimate.
The beginning of a new school year brings a lot of legitimate communication, often from several different places. Parents may receive emails from teachers, school administrators, after-school programs and payment platforms asking them to complete forms, update contact information, create accounts or pay for lunches, activities, equipment and school trips. University students receive their own stream of messages about enrollment, tuition, accommodation, financial aid, student loans and university accounts.
All this communication creates useful cover for scammers. Instead of inventing an unusual story, they can imitate something parents or students are already expecting. And the timing can make the message particularly convincing.
The UK's Student Loans Company (SLC), for example, says criminals target students around student-loan payment periods in September, January and April, using emails, texts and phone calls claiming that something has gone wrong with an upcoming payment.
With approximately £2.6 billion in maintenance support scheduled to reach 1.1 million students in September, SLC is warning students about scam messages claiming that payments have been blocked, bank details need updating, or accounts are at risk of being closed.
Scammers can take advantage of almost any routine school-related message or request. Here are seven common examples to watch for.
A parent receives an email or text that appears to come from the school asking for payment for lunches, books, supplies, a field trip, sports or another activity. The amount may even be relatively small, making the request seem less suspicious.
The link, however, takes you to a fake payment page designed to steal card details, login credentials or other personal information.
A message might claim that a school payment failed, your child's lunch account has insufficient funds, a tuition payment is overdue, or an outstanding balance must be settled before a deadline.
For university students, the same technique can be used with tuition, accommodation or student finance.
"Log in to see your child's timetable."
"There's a new message from your child's teacher."
"Please review the attached school document."
The link may lead to a website that looks almost identical to the school's real parent portal, learning platform or university login page. If you enter your username and password, however, those credentials go to the scammer. Once criminals have access to an email, school or university account, they may be able to collect more personal information or use the compromised account to target other people.
The start of the school year is also when schools legitimately ask families to confirm contact details, emergency contacts, medical information or other records. That makes a fake "Please update your child's information" message particularly believable.
A fraudulent form could ask for names, dates of birth, addresses, phone numbers, email addresses and other personal information that could later be used for identity theft or more targeted scams.
The SLC specifically warns students not to share details such as their name, date of birth, customer reference number, course information, or current or previous address online because criminals can use this information to impersonate them.
If a teacher, employee or school account has been compromised, criminals may be able to send phishing messages from a legitimate email address.
That makes the usual advice to "check the sender" less useful. A message from a familiar account should still be questioned if the request itself is unusual, particularly if it asks you to make a payment, provide sensitive information, enter login credentials or act urgently.
A QR code in an email, poster, flyer or message can lead to a phishing page just as easily as a regular link. A fake QR code might take you to what appears to be a school payment page, registration form or login portal. Because you can't necessarily see where a QR code leads before scanning it, the destination may also be harder to judge.
Perhaps the school really is collecting money for a trip. Registration really does close this week. Your university really is processing student finance. Or your child's school really did send parents a message about a new portal.
A scammer can use publicly available information, social media posts or details obtained through a compromised account to make a fraudulent message fit what is actually happening.
If a message asks you to make a payment, log in to an account or provide personal information, don't rely on the message itself to decide whether it's legitimate. Verify the request independently.
For example, the UK's Student Loans Company (SLC) says it will never ask students to provide or confirm personal or financial information by email, text message or social media, or threaten to close an account if they don't respond within an urgent deadline.
SLC and Student Finance England also don't provide services through WhatsApp or initiate contact through social media to discuss a student's finance application or entitlement. Students who receive an unexpected message about their student finance should avoid the link provided and log in to their account independently through GOV.UK.
According to SLC, its fraud prevention measures saved £56.2 million last year.
The same principle applies to messages supposedly coming from a school, teacher, university or payment service:
If you're still unsure about a link or message, Bitdefender Scamio can help you check suspicious emails, texts, links and QR codes before you act, while Bitdefender Link Checker lets you check whether a URL is safe before opening it.
For families looking for broader protection, Bitdefender Family Plans combine security and scam protection across family devices with tools that can help parents protect their children's digital lives.
If you entered a password on a suspicious page, change it immediately on the real account. If you reused the same password elsewhere, change it on those accounts too.
Enable multi-factor authentication where available and check the affected account for unfamiliar activity or changes.
If you shared card or bank information or made a fraudulent payment, contact your bank or payment provider as soon as possible.
Also notify the school or university if the scam impersonated a teacher, administrator or school system. Other families or students may be receiving the same message, and the institution may need to investigate whether an account has been compromised.
Report the scam to the relevant authorities and if money was stolen or your banking information was compromised, contact your bank immediately.
You may also want to read:
Check whether the request is unusual, urgent or asks for passwords, payment details or personal information. Don't rely only on the sender's address, as legitimate school email accounts can be compromised. Instead, contact the school independently or check the request through its official website, app or parent portal.
Some schools use email or text to notify parents about legitimate payments, but the process varies by school. If you receive an unexpected request, don't pay through the message itself. Check the school's official payment platform or contact the school directly to confirm it.
Yes. Scammers can spoof email addresses or take over legitimate teacher or school accounts. A familiar sender therefore doesn't guarantee that a message is safe. Be cautious of unexpected requests for money, passwords, verification codes or personal information.
Not necessarily. A QR code can lead to a phishing or fraudulent website just like a regular link. Before entering login, payment or personal information after scanning one, make sure the destination belongs to the school, university or service you expect.
If you entered a password, change it immediately and change it anywhere else you reused it. Enable multi-factor authentication and check the account for suspicious activity. If you provided payment or banking information, contact your bank or payment provider. You should also notify the school or university about the scam.
tags
Cristina Popov is a Denmark-based content creator and small business owner who has been writing for Bitdefender since 2017, making cybersecurity feel more human and less overwhelming.
View all posts