Is a university bursary or grant email I didn't apply for real?
No. Unsolicited bursary or grant emails targeting students are phishing attacks or advance-fee scams.
Last reviewed: 1 August 2026
Explanation
Students are targeted by scam emails claiming they have been selected for a bursary, emergency fund, or educational grant. The email appears to come from the university financial aid office, a charitable foundation, or a government body. To claim the money, you are asked to click a link and verify your student portal credentials — which are then stolen — or you are told to pay a small processing fee to release the funds. Genuine university bursaries require you to apply, are communicated through official student portal notifications, and never charge a fee to receive funds. If you receive an unsolicited award notification, verify it by contacting your student services office directly.
These campaigns cluster around the points in the academic year when money is tight — enrolment, exam periods, and the weeks before loan instalments arrive. Compromised student accounts make the problem worse: once one mailbox is taken over, the scam is re-sent internally, so a message from a fellow student's address is no guarantee of safety. Stolen portal credentials are valuable in their own right, giving access to personal data, coursework, and sometimes the ability to redirect payment details.
Treat any financial award you did not apply for as unverified until student services confirms it. Use contact details from the university's own website, not those in the message, and encourage coursemates who received the same email to report rather than click.
Common red flags
- Award notification arrives unsolicited for something you never applied for
- Link leads to a credential login page outside the university domain
- Processing fee required before funds are released
- Email addresses you generically — 'Dear Student' — not by name
- Urgent deadline to claim the funds
What to do now
- Do not click links or pay any fees
- Contact your university student finance office directly to verify
- If you entered credentials, change your student portal password immediately
- Report the email to your university IT security team
Frequently asked questions
What if the email came from an address that looks like my university?
Email domain spoofing allows senders to imitate official-looking addresses. Always go directly to your official student portal rather than clicking email links.
I clicked the link but did not enter my login — am I at risk?
Clicking alone is usually low risk, but change your password if you are unsure what the page did, and report the link to your university IT team so they can warn other students and block the domain.