HackMyIP
← Back to News
2026-08-18 The Record

University of Texas at San Antonio Takes Systems Offline After Cyberattack

Incident ResponseRansomwareVulnerability

The University of Texas at San Antonio (UTSA), one of the largest universities in Texas serving 40,000 students across six campuses, was forced to take critical systems offline on Monday after its IT team detected threat activity over the weekend. Chief Technology Officer Michael Schnabel confirmed that the suspicious activity was identified at the edge of the university's network and was contained before it could reach core systems and University Technology Solutions. In response, UTSA pulled the plug on multiple services—including phone systems—hours before classes were scheduled to begin on Wednesday. The outage threatened to disrupt course registration, student payment portals, and other essential academic services. While no hacking group has claimed responsibility, the incident fits a troubling pattern of threat actors targeting universities during the start and end of academic terms to maximize leverage for extortion.

In an official statement, Schnabel emphasized that the ongoing investigation had found "no evidence that university data was accessed or exfiltrated as a result of this activity." However, the defensive isolation of affected systems created cascading operational problems. The university extended its student payment deadline to Friday and modified course waitlist procedures, while a mandatory password reset for all students and faculty was announced on Monday night. By Tuesday, UTSA warned that the password reset initiative was experiencing significant delays, leaving many users locked out. This kind of incident response fatigue is common during active threats, and users should independently verify their credentials haven't been compromised using a trusted password strength and breach checker to ensure their new passwords meet strong security standards.

UTSA's targeted edge-of-network containment strategy mirrors the defensive posture adopted by other major universities that have suffered similar attacks. The University of Oklahoma, Stanford, and the University of Michigan all faced ransomware intrusions following holiday breaks, while the University of Pennsylvania saw its email systems disrupted in October during a separate cybersecurity incident. Columbia and Harvard Universities were also targeted last year. In May, a damaging cyberattack on a critical education software provider forced universities nationwide to delay final exams, highlighting how supply-chain vulnerabilities in the higher education sector continue to expose institutions to downstream risk. Security teams monitoring perimeter infrastructure can use tools like a port scanner to identify exposed services that could serve as initial access points for attackers.

As UTSA continues its recovery and investigation, the university is urging students to remain patient as it works to restore systems securely ahead of the new academic year. Faculty and staff are advised to set strong, unique passphrases and remain vigilant for phishing attempts that often follow announced breaches. Given the volume of credential exposure incidents in the education sector, students and employees can proactively run an email breach checker to confirm their accounts have not surfaced in known leak databases. The incident underscores the critical importance of layered network defenses, rapid incident response playbooks, and robust endpoint monitoring for institutions managing large, distributed user bases.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →