Back-to-school scams target parents, students and businesses
Warnings issued by Vietnamese law enforcement authorities in August and early September 2026 show that back-to-school scams are no longer limited to simple requests for money. Fraudsters may impersonate teachers, school staff or public authorities, create fake documents and payment instructions, and use psychological pressure to manipulate students and their families.
The back-to-school season brings a surge of payments, enrollment procedures and administrative communications for parents, students and first-year university students. Tuition fees, uniforms, textbooks, accommodation and other school-related expenses often need to be handled within a short period of time.
That combination of urgency and frequent transactions is increasingly being exploited by scammers.
Scammers impersonate schools and teachers to demand payments
One of the most common schemes at the beginning of the school year involves impersonating teachers or school employees.
In a warning published on September 7, 2026, authorities said scammers may collect information about students and parents from social media, class groups or other publicly accessible sources before contacting their targets.
The fraudsters can then pose as homeroom teachers, administrative staff, accountants or school representatives and request payments for seemingly legitimate purposes such as tuition fees, textbooks, insurance, uniforms, learning materials or extracurricular activities.
Because scammers may already know a student's name, class or school, fraudulent messages can appear highly convincing.
The risk therefore lies not only in whether the message itself sounds reasonable. Parents also need to consider whether the communication channel, sender identity and payment account actually match the school's official information.

Fake tuition notices, accommodation scams and “online kidnapping”
University students and first-year students face an even broader range of risks.
On August 25, 2026, Hai Phong City Police warned of several scams targeting students during the back-to-school period.
One method involves creating fake admission notices, scholarship announcements or enrollment documents containing copied logos, signatures or stamps. Victims are then instructed to pay tuition fees or administrative charges into accounts controlled by scammers.
Accommodation is another area frequently exploited.
Fraudsters may advertise rental rooms in convenient locations using attractive images and unusually low prices, then pressure students to transfer a deposit before viewing the property. Once the money is sent, the supposed landlord disappears or cuts off communication.
Authorities have also highlighted a more serious form of psychological manipulation commonly referred to as “online kidnapping.”
In these cases, scammers may impersonate law enforcement officers and falsely accuse students of being involved in criminal investigations. Victims may be ordered to keep the situation secret, stop contacting their families or isolate themselves in a hotel or another location.
Once the victim is psychologically controlled, scammers can use the situation to demand money from either the student or their family.
Although the scenarios differ, they share one important characteristic: the victim is placed under intense pressure to act quickly.
Fear, urgency or the threat of losing an important opportunity can make people less likely to independently verify what they are being told.
Businesses can also become victims of education-related impersonation scams
The same impersonation tactics are not limited to parents and students.
On May 18, 2026, authorities in Can Tho received a report from a business owner who had been approached by individuals allegedly impersonating Tay Do University.
According to the police warning, the scammers contacted the business to place a large order for metal beds. To make the transaction appear legitimate, they reportedly used images of fake employee identification cards and forged documents.
The business was then asked to transfer VND 100 million as an advance payment related to the transaction.
The case illustrates how the same social engineering principle can be adapted to different victims.
For a parent, the message may be framed as a tuition payment request. For a company, it may appear as a purchase order, supplier transaction, deposit request or payment instruction from what seems to be a legitimate organization.
This expands the issue beyond consumer fraud and into a broader cybersecurity and business risk.
Impersonation attacks expose weaknesses in business processes
For organizations, the most important lesson is that cybercrime does not always begin with sophisticated malware or the exploitation of a technical vulnerability.
Attackers can also exploit trust.
Company websites, social media profiles and public business information may reveal employee names, job titles, suppliers, partners and contact information. Those details can then be incorporated into highly convincing impersonation attempts.
Employees working in accounting, procurement and sales are particularly exposed because their roles routinely involve payment requests, contracts and communications with external parties.
An unexpected change in bank account information, an urgent request for a deposit, a new contact claiming to represent a familiar organization or an unusual payment instruction should therefore be treated as more than an administrative issue.
They may be indicators of social engineering or payment fraud.
Organizations should consider whether their internal processes require independent verification before unusual financial transactions are approved, especially when requests involve new payment accounts or significant amounts.
👉Cybersecurity awareness also remains important. Employees need to understand how phishing, identity impersonation and social engineering work, while businesses should protect email accounts, use multi-factor authentication and maintain clear procedures for escalating suspicious requests.
Back-to-school scams reflect a wider social engineering problem
The back-to-school period creates ideal conditions for fraud: large volumes of communication, frequent payments and strong pressure to complete procedures quickly.
Attackers do not necessarily need to compromise a complex IT system. In many cases, they only need to impersonate the right person, approach the victim at the right moment and make a request that appears believable.
For parents and students, these scams highlight the importance of verifying unexpected communications through trusted channels.
For organizations, however, the lesson extends further.
Impersonation, phishing and payment fraud demonstrate why cybersecurity should address not only technology, but also people and business processes. As attackers increasingly use publicly available information and social engineering to make fraudulent requests more convincing, identity verification and transaction controls are becoming an important part of organizational security.
The specific scenario may change, but the underlying method remains similar: establish credibility, create urgency and persuade the victim to act before independently verifying the request.
For businesses, this is a reminder that cybersecurity risk does not stop at networks, applications or endpoints. Protecting employees, communication channels and financial approval processes is equally important in reducing exposure to modern social engineering attacks.
References
Vietnam Ministry of Public Security - Warning on scams impersonating schools and teachers at the beginning of the new school year
Vietnam Ministry of Public Security - Hai Phong Police warn of scams targeting students and first-year university students during the back-to-school season
Vietnam Ministry of Public Security - Can Tho Police warn about back-to-school scam tactics
Vietnam Cybersecurity Magazine - “Back-to-school scams surround parents during the new school year”










Comments