UTSA cyberattack attempt shows how quickly threats can target universities, cybersecurity expert says
The university says the attempted breach was stopped before reaching core systems; Expert urges institutions to prepare for attackers getting inside
Matthew Craig, Photojournalist
Published: August 19, 2026 at 10:43 PM
SAN ANTONIO – A new semester at the University of Texas at San Antonio was scheduled to begin Wednesday. Instead, students are waiting another week to return to class after the university detected an attempted cybersecurity breach and took some systems offline as a precaution
UTSA said the attempted attack was stopped before reaching its core systems. The university has not said student or university data was stolen, and officials have emphasized that the investigation and security response are ongoing
The attempted attack has disrupted some online services and forced the university to adjust several deadlines as it works to restore systems and prepare for the delayed start of the fall semester
But cybersecurity experts say the attempted breach also illustrates a much larger problem facing universities and other large organizations: attackers do not necessarily need days or weeks to find a target
They may need only minutes
Richard Hummel, vice president of threat Intelligence at SecurityScorecard, has spent nearly two decades working in cybersecurity, including threat intelligence involving nation-state actors, cybercriminals and other malicious groups
His team monitors cybercriminal activity worldwide, including claims made on hacker forums, messaging platforms and social media
When an attacker claims to have breached an organization, Hummel said security researchers initially treat that claim as an allegation. Researchers then look for evidence confirming whether the breach actually occurred
That can include public disclosures from an organization, evidence that stolen data is being sold or confirmation from other
Hummel said the speed at which attackers scan for vulnerable systems is a separate and increasingly urgent concern. But he said the basic lesson remains the same
“The moment a device comes online, has a public IP address, it’s available for anything out there to scan,” Hummel said
For organizations, that means cybersecurity defenses must be in place before a system connects to the internet — not after an attack begins
Universities face a particularly complicated cybersecurity environment. Thousands of students, faculty and staff may connect personal computers, phones, tablets and other devices to university networks. Unlike a traditional corporate environment, a university has less control over many of those devices
That creates more potential entry points for attackers. Hummel said the university’s ability to stop the attempted breach before it reached its most critical systems is an important distinction
“The fact that they were able to catch this and stop this before it hit critical systems speaks to the fact that they’re doing a lot of the right steps,” he said
He pointed to network isolation, permissions and other security controls as potential reasons an organization can prevent an intrusion from spreading
UTSA has not publicly detailed the specific techniques it used to stop the attempted attack
Cyberattacks have traditionally required a certain level of technical knowledge. An attacker might have needed to understand networking, identify a target’s systems, conduct reconnaissance and create or modify tools to exploit a vulnerability
Hummel said artificial intelligence is changing that equation. Cybercriminals have increasingly used automated tools and AI agents to help determine how to attack a target, he said. Some systems can help users move from identifying a target to selecting potential attack methods
Hummel said unrestricted AI models could make that process even easier
“There is zero barrier to entry anymore,” he said. “If you have a computer and you have the internet, you have the capability.”
That does not mean every internet user is capable of successfully breaching a major university, but Hummel said the tools have lowered the technical knowledge needed to attempt malicious activity
So what are attackers after? For many cybercriminals, the answer is money
Hummel said criminal groups can operate much like businesses, with different participants specializing in areas such as stealing information, hosting infrastructure, moving money or distributing spam
Ransomware groups, for example, may steal data and encrypt systems before demanding payment
Some groups use multiple forms of extortion, threatening to keep systems locked, publish stolen information or launch additional attacks if victims refuse to pay. The common factor, Hummel said, is that large organizations have to prepare for multiple types of threats
Hummel said organizations need to identify the systems they absolutely cannot afford to lose and make sure those systems are protected and capable of continuing to operate even during an attack
Hummel recommends people learn what common cyberattacks look like
Phishing emails, fraudulent password resets and unexpected multifactor authentication requests can all be used to trick people into giving attackers access. He added that people should not assume they are too smart or too careful to become victims
Think about which accounts would cause the greatest problems if they were compromised, he said. That could include email, banking, credit cards and other financial accounts
Using unique passwords, a password manager and multifactor authentication can reduce the risk that one compromised password will provide access to multiple accounts
For now, the attempted breach at UTSA is still being investigated, and the university has not indicated that its core systems were compromised
But Hummel said institutions should view incidents like this as a reminder that cyberattacks are no longer unusual events reserved for the largest technology companies
Read also:
- Students share mixed reactions as UTSA’s fall semester delayed amid attempted data security breach
Copyright 2026 by KSAT – All rights reserved

