UT San Antonio Cyber Incident Disrupts Start of Term
University takes systems offline after detecting unauthorized activity, delaying registrations and payments ahead of the fall semester.
As thousands of students prepared to begin the fall semester at the University of Texas at San Antonio, a cyber incident threw campus technology into turmoil, forcing administrators to take systems offline and leaving many unable to register for classes or pay tuition just days before instruction started.
Unauthorized Activity Detected at Network Edge
University leaders revealed on August 17 that they had identified what they described as “attempted unauthorized activity” at the edge of their network, before it could reach core systems.
In response, University Technology Solutions (UTS) acted quickly with expert partners to contain the activity. This involved taking some systems offline to allow for a thorough evaluation of the environment and to assess whether additional protections are needed.
Containment Measures Effective So Far
UT San Antonio stated that its response has been effective, with no evidence so far that any data was accessed or exfiltrated as a result of the unauthorized activity.
While the university expressed confidence in its containment, it acknowledged that the shutdown is causing significant disruption for its community ahead of the semester's start on August 19.
Disruptions to Registration and Payments
The outages have directly affected online registration and tuition payments, processes that are already stressful for students at the beginning of a term. The university said extensions have been granted for students to complete these essential tasks.
University phone systems were unavailable as of a 12:30 p.m. CST update on August 17, though they were expected to be restored later that day.
Passphrase Resets Ordered
In an update on the university’s Facebook page at 5:30 p.m. CST on August 17, officials said students, faculty, and staff would receive instructions to reset their passphrases on Tuesday, August 18.
This step is a precautionary measure, ensuring that even if credentials were somehow compromised, they would be invalidated.
Why This Timing Matters
The incident comes at a particularly sensitive time for educational institutions, which have been heavily targeted by cyber-attacks at the start of the academic year in recent years.
IT systems are often stretched to their limits during registration and enrollment periods, making them more vulnerable and disruptions more impactful.
“Taking major systems offline at that moment creates immediate pressure to get everything running again. Whether that timing was intentional isn’t clear. Still, attackers understand that disruption carries more weight when an organization is already operating at maximum capacity. Universities are no different from hospitals or retailers in that respect. The more painful downtime becomes, the more leverage an attacker potentially gains.”
— Ross Filipek, CISO at Corsica Technologies
Filipek praised UT San Antonio for detecting and containing the incident early but stressed the importance of network segmentation to prevent wider systems from being affected by such measures.
Balancing Security and Operations
“Cyber resilience means being able to contain a threat without forcing the rest of the organization to choose between security and keeping the doors open,” he said.
For the university, the immediate priority is restoring normal operations while ensuring the environment is secure. For students and staff, the ongoing uncertainty about when full functionality will return could have lasting effects on enrollment and academic continuity.
What This Means for Other Institutions
This incident underscores a broader lesson for universities and colleges: cyber-attacks are becoming a predictable hazard at the start of term, and the cost of downtime is measured not just in data loss but in lost student trust and disrupted academic lives.
Institutions may need to reconsider their contingency planning, ensuring that critical services like registration can survive an incident without forcing a total shutdown. For students, the takeaway is practical: keep an eye on official communications, reset passphrases as instructed, and be prepared for potential delays as schools work to recover.
Sources
- Infosecurity Magazine Original source
Continue Reading
RubyGems Poisoned: Supply Chain Risk Beyond Typos
OpenSourceMalware finds 16 typosquatted RubyGems, but the real risk is package name reuse and unvalidated author fields.
Task Host Flaw Now a Ransomware Tool
CISA confirms ransomware gangs are exploiting a Windows Task Host privilege escalation flaw added to KEV in April.
AI Misuse Warning Hits UK Legal Sector
SRA flags AI hallucinations and data leaks in legal work, urges stronger oversight.