Published · 4d agoSecurity3 min read
Contained at the edge, offline at the worst week: UTSA's shutdown before 40,000 students returned
The University of Texas at San Antonio says the intrusion never reached core systems. It still took phones, course registration and tuition payments down with classes two days out.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The University of Texas at San Antonio said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response; the attack was announced on Monday morning.
- Classes for many UTSA students begin on Wednesday.
- UT San Antonio's term started on August 19, and the university's statement was released on August 17.
- The University of Texas at San Antonio serves 40,000 students across six campuses.
- The disruptions from the systems shutdown impacted online registration and tuition payments, and extensions were granted for students to complete those processes.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The University of Texas at San Antonio said on Monday morning that its IT team had identified threat activity on its academic campus over the weekend and had taken some systems, including phones, offline in response [1]. Classes for many students started two days later, on Wednesday, August 19 [2][3], which is how a containment decision at a 40,000-student, six-campus institution turns into a registration and payments story [4][5].
The framing from the university is narrow. Chief technology officer Michael Schnabel said the activity was detected at the edge of the network and contained before it reached "core systems and University Technology Solutions" [6], and that the investigation had so far found no evidence that university data was accessed or exfiltrated [7]. UTSA did not respond to questions about what was impacted [8], and no group has claimed credit [9].
Edge containment is the good outcome. It was also not free. According to Infosecurity Magazine, University Technology Solutions worked with outside partners to contain the activity, and taking systems offline was part of that response, so the environment could be evaluated and additional protections assessed [10]. The visible damage, in other words, was largely self-inflicted by design: the outage bought the investigation room. What it cost was online registration and tuition payments in the week those two things matter most [5].
The concessions track the calendar rather than the incident. The student payment deadline moved to Friday and course wait lists were adjusted [11][12], an extension of about four days from Monday's announcement and two days past the first day of classes [13]. Phone systems were down as of a 12:30pm CST update on August 17 and were expected back later that day [14]. A Facebook post at 5:30pm the same day said students, faculty and staff would get passphrase reset instructions on Tuesday [15]; the university planned a reset for all students and teachers [16], then said on Tuesday that the effort was hitting delays [17]. A universal credential reset during add/drop week is the sort of remediation that competes directly with the thing the institution exists to do that week.
Ross Filipek, CISO at Corsica Technologies, told Infosecurity Magazine that taking major systems offline at that moment "creates immediate pressure to get everything running again," that it was not clear whether the timing was intentional, and that attackers understand disruption carries more weight when an organization is already at maximum capacity [18]. He credited UTSA with early detection and containment but pointed at segmentation as the control that keeps containment from becoming an outage [19].
The seasonality is not new. Criminals have repeatedly hit universities at the start and end of terms to force large ransom payments [20]. In May, US universities delayed final exams after an attack on an education software provider [21]; Oklahoma, Stanford and Michigan have taken ransomware hits after holiday breaks [22]; Penn's email was disrupted in October [23], and Columbia and Harvard were both attacked last year [24].
Watch whether the password reset finishes without another slip, whether the Friday payment deadline holds, and whether UTSA ever publishes what "some systems" meant. An institution that says nothing was exfiltrated but will not say what went dark is asking to be believed on both counts.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The University of Texas at San Antonio said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response; the attack was announced on Monday morning.
ReportedView cited source - [3]
UT San Antonio's term started on August 19, and the university's statement was released on August 17.
ReportedView cited source - [4]
The University of Texas at San Antonio serves 40,000 students across six campuses.
ReportedView cited source - [5]
The disruptions from the systems shutdown impacted online registration and tuition payments, and extensions were granted for students to complete those processes.
ReportedView cited source - [6]
Chief technology officer Michael Schnabel said the threat activity was detected at the edge of the university's network and was contained before it reached "core systems and University Technology Solutions."
ReportedView cited source
Sources & coverage · 5 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- infosecurity-magazine.com5d agoCyber Incident Disrupts Student Services at UT San Antonio
- therecord.media5d agoUniversity of Texas forced to take systems offline in San Antonio after cyberattack
- news.utsa.edu4d agoUT San Antonio



