Breaking
SecurityDeveloping Story

UT San Antonio Cyber Incident Disrupts Start of Term

University takes systems offline after detecting unauthorized activity, delaying registrations and payments ahead of the fall semester.

··2 hours ago·3 min read
black ImgIX server system
Photo by imgix on Unsplash

As thousands of students prepared to begin the fall semester at the University of Texas at San Antonio, a cyber incident threw campus technology into turmoil, forcing administrators to take systems offline and leaving many unable to register for classes or pay tuition just days before instruction started.

Unauthorized Activity Detected at Network Edge

University leaders revealed on August 17 that they had identified what they described as “attempted unauthorized activity” at the edge of their network, before it could reach core systems.

In response, University Technology Solutions (UTS) acted quickly with expert partners to contain the activity. This involved taking some systems offline to allow for a thorough evaluation of the environment and to assess whether additional protections are needed.

Containment Measures Effective So Far

UT San Antonio stated that its response has been effective, with no evidence so far that any data was accessed or exfiltrated as a result of the unauthorized activity.

While the university expressed confidence in its containment, it acknowledged that the shutdown is causing significant disruption for its community ahead of the semester's start on August 19.

Disruptions to Registration and Payments

The outages have directly affected online registration and tuition payments, processes that are already stressful for students at the beginning of a term. The university said extensions have been granted for students to complete these essential tasks.

University phone systems were unavailable as of a 12:30 p.m. CST update on August 17, though they were expected to be restored later that day.

Passphrase Resets Ordered

In an update on the university’s Facebook page at 5:30 p.m. CST on August 17, officials said students, faculty, and staff would receive instructions to reset their passphrases on Tuesday, August 18.

This step is a precautionary measure, ensuring that even if credentials were somehow compromised, they would be invalidated.

Why This Timing Matters

The incident comes at a particularly sensitive time for educational institutions, which have been heavily targeted by cyber-attacks at the start of the academic year in recent years.

IT systems are often stretched to their limits during registration and enrollment periods, making them more vulnerable and disruptions more impactful.

“Taking major systems offline at that moment creates immediate pressure to get everything running again. Whether that timing was intentional isn’t clear. Still, attackers understand that disruption carries more weight when an organization is already operating at maximum capacity. Universities are no different from hospitals or retailers in that respect. The more painful downtime becomes, the more leverage an attacker potentially gains.”

— Ross Filipek, CISO at Corsica Technologies

Filipek praised UT San Antonio for detecting and containing the incident early but stressed the importance of network segmentation to prevent wider systems from being affected by such measures.

Balancing Security and Operations

Cyber resilience means being able to contain a threat without forcing the rest of the organization to choose between security and keeping the doors open,” he said.

For the university, the immediate priority is restoring normal operations while ensuring the environment is secure. For students and staff, the ongoing uncertainty about when full functionality will return could have lasting effects on enrollment and academic continuity.

What This Means for Other Institutions

This incident underscores a broader lesson for universities and colleges: cyber-attacks are becoming a predictable hazard at the start of term, and the cost of downtime is measured not just in data loss but in lost student trust and disrupted academic lives.

Institutions may need to reconsider their contingency planning, ensuring that critical services like registration can survive an incident without forcing a total shutdown. For students, the takeaway is practical: keep an eye on official communications, reset passphrases as instructed, and be prepared for potential delays as schools work to recover.

#cyber incident#university#ut san antonio#network security#disruption#education

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories