An ad circulating on social media promises to take online courses for you. What it collects is your login, what it sells is your reputation, and there’s no statute of limitations on either.


by Tim Leogrande, BSIT, MSCP, Ed.S.

🗓 SEP 10 2026 • 6 MIN 30 SEC READ

📝  ESSAY


Earlier this week, a few colleagues were discussing the web advertisement below, which has been circulating on social media.

D82A4421-EFB4-4875-B0CA-4803DB7171B7.png

The ad promotes the Global Classes Help cheating-as-a-service firm for college students. It claims they can circumvent several proctoring solutions such as LockDown Browser, ProctorU, and Examplify. It also lists Edgenuity, a platform for high school students.

There is a short list of several schools whose students the firm is targeting. Some of them, like Sophia, Study.com, and StraighterLine, aren’t actually schools; they sell courses that transfer into credit-granting institutions. Others are real universities: Western Governors University (where I’m on the faculty), Southern New Hampshire University, and University of Phoenix.

At the bottom is a banner of logos corrupted by the AI platform that generated the ad. One logo reads “Howvrlock.” Apparently, it mangled Honorlock, which is another online proctoring service. There is also the smeared remnants of the Examplify logo and “FCK POSTER,” which I’d like to believe is an indication of what the chatbot thinks of the person who fed it the prompt.

The scammers behind these ads describe their services as proctoring assistance, then turn around and claim they will help you circumvent those same proctoring solutions, ostensibly so they can log in to take exams for you.

But contract cheating services are extortion in a cardigan. This isn’t the first such operation I’ve seen, but I’ve held off writing about this subject because most of the coverage I had read framed it as an insider threat and nothing more. Only recently have I seen it framed as extortion, so I’ll discuss both.

Here’s how it works:

Extortion is the point, and the advertised cheating service is just the victim-acquisition strategy. Students are extorted under threat that their cheating will be reported to the university, that evidence of academic dishonesty will be shared with the dean, and that the dean will see it in the form of incriminating documents and impossible travel. The scammers log into student accounts using residential, mobile, and proxy IPs (through VPNs) in Kenya. Suddenly, a student has authenticated into their school’s portal from their home in the U.S. and then from Nairobi, sometimes just minutes apart. It’s convenient for deans to have that sort of evidence, which is exactly why it’s manufactured.