The University of Texas at San Antonio took multiple IT systems offline after detecting attempted unauthorized activity at the edge of its network, prompting emergency containment measures before the activity reached core systems. The disruption affected online registration, tuition payment services and university phone systems just ahead of the August 19 start of the academic term, while University Technology Solutions worked with external cybersecurity partners to investigate and contain the incident.
University officials said there was no evidence at the time of reporting that data had been accessed or exfiltrated, but students, faculty and staff were told to expect instructions to reset their passphrases. The incident adds to a broader pattern of cyber disruptions targeting educational institutions during back-to-school periods, when operational pressure and user activity are high.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
UT San Antonio delayed the start of the semester following the attempted cybersecurity breach and related IT disruptions. This marks an escalation from service interruptions to a direct impact on the university's academic schedule.
In a Tuesday update, UT San Antonio said the password reset process for students and teachers was experiencing delays. The reset had been announced the previous day as part of the university's response to the cyber incident.
A Facebook update posted at 5:30 p.m. CST on August 17 said students, faculty, and staff would receive instructions to reset their passphrases on Tuesday, August 18. The reset guidance was part of the university's response to the incident.
A 12:30 p.m. CST update on August 17 said the university's phone systems were still unavailable. UT San Antonio said it expected phone services to be restored later on August 17.
In a statement released on August 17, university leaders disclosed the cyber incident and said the containment response had disrupted online registration, tuition payment services, and phone systems. The university granted extensions for students to complete registration and tuition payment processes.
UT San Antonio identified attempted unauthorized activity at the edge of its network before it reached core systems. University Technology Solutions, working with external partners, took some IT systems offline for containment and evaluation, and the university said there was no evidence that data had been accessed or exfiltrated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcesanantonioreport.org
Open sourcetherecord.media
Open sourceinfosecurity-magazine.com
Open sourcedysruptionhub.com
Open sourcenews.utsa.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.