Menu
Browse

Cyber Incident Victim: University of Texas at San Antonio

Date

Aug 2026

Location

United States of America

Status

Ongoing

Updated

2026-08-22 12:26

Timeline
Occurred
Undetermined
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

University of Texas at San Antonio delayed the start of its semester after a cybersecurity breach was detected over the weekend, prompting officials to cut access to some online services while they contained the threat and investigated. Students, faculty and staff experienced limited or no access to university accounts, and the password reset process was postponed as officials worked to restore systems. Payment deadlines were extended, phone service was interrupted, and waitlist and registration functions were gradually brought back online as the investigation continued with no evidence of a data breach found.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Over the weekend of August 15‑16 2026, university security personnel detected unauthorized activity targeting the technology systems of the University of Texas at San Antonio at the edge of its network before it reached core systems. In response, University Technology Solutions, working with expert partners, took immediate action to contain the activity and protect the campus technology environment. Officials subsequently cut access to some online services as part of the containment effort while the investigation continued. As of Tuesday morning, the process of resetting passwords had been delayed, and phone systems were down with restoration expected later that day. The university’s senior leadership, including President Taylor Eighmy, Andrea Marks, and Michael Schnabel, stated that the containment actions were deemed effective and that the ongoing investigation had not found evidence of a data breach.

Cyber Incident Image

Because of the proximity to the originally scheduled start of the fall 2026 semester on August 19 and the impact on payment deadlines, the university announced a delay of the semester start to Monday, August 24, to allow teams time to restore services carefully. Payment deadlines were extended until Friday, August 21 at 5 p.m., waitlists were being restored, and registration for the fall semester remained open. University operations continued as scheduled, with faculty and staff maintaining normal work schedules to ensure students had access to needed services and support. Students, faculty, and staff were informed that they would receive notices and instructions to reset their university account passwords, referred to campus‑wide as “passphrases,” and were advised to wait for that communication before beginning the reset process. The university emphasized that these adjustments were intended to give additional time and flexibility while technology services were being restored.

The investigation into the incident remained ongoing, and university officials said they would take additional steps to protect accounts and systems as needed. Officials reiterated that the activity had been detected at the network edge and that core systems had not been compromised. They also noted that the exact identity of those behind the cyberattack was still unclear. The university committed to providing further updates to the community as the situation evolved.

Sources
Sources available to members
3 sources