It would be difficult for an unknown individual or unknown/untrusted organisation.
It's less difficult for a respected university willing to sacrifice its reputation.
The patches for the study were submitted from Gmail addresses. It wasn't tied to the university and didn't even use university email addresses. I don't know why people keep repeating this misinformation, including kernel developers.