Skip to content

UT San Antonio systems outage after attempted intrusion

Summary

The University of Texas at San Antonio logo

Classes resumed Aug. 24, major services returned and the current technology-alert page showed ordinary planned maintenance rather than continuing incident recovery. The incident is presumed resolved, although the university has not issued an incident-wide all-clear.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Authentication disruption

    Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Website unavailable

    A public-facing website was unavailable, disabled, or inaccessible.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

UT San Antonio first acknowledged Aug. 15 that UTSA.edu was inaccessible and redirected users to UT San Antonio Today while restoration work continued. On Aug. 17, the university said it had detected attempted unauthorized activity at the edge of its academic-campus network over the weekend. University Technology Solutions and outside specialists contained the activity before it reached core systems, then proactively took some systems and services offline for evaluation and additional safeguards. The university’s description of unauthorized activity provides concrete evidence of cyber involvement even though the public record does not establish a successful intrusion into core systems.

The university said its response was effective and that the continuing investigation found no evidence that university data was accessed or exfiltrated. No public source identified ransomware, malware, a ransom demand or a responsible party. Searches using the university’s name and utsa.edu found no stable ransomware or extortion victim claim.

Operational significance

The disruption affected UT San Antonio’s academic-campus technology environment, not the Health Science Center. It made the public website unavailable and disrupted university accounts, registration, payments, course information, waitlists and phone service immediately before the fall semester. The university extended payment and course-add deadlines, restored waitlist positioning and required university-wide passphrase resets.

On Aug. 18, the university delayed the first day of fall classes from Aug. 19 to Aug. 24 so teams could continue restoring connectivity, email and other essential services. On Aug. 20, it said more systems and services were returning each day and began phased student passphrase resets. Extended technology-access support continued through Aug. 25.

A One Stop update dated Aug. 25 said financial-aid refunds would resume as necessary technology systems came online. It also said phone lines were available and student passphrase resets could be completed, documenting substantial recovery but not full restoration.

Disclosure posture

UT San Antonio’s Aug. 15 public message described a website-access issue without cyber or security wording. Its Aug. 17 notice supplied the first identified affected-organization cyber characterization by describing attempted unauthorized activity at the network edge. No earlier credible external cyber characterization or stable actor claim was identified, so DysruptionHub assesses the disclosure sequence as organization-first.

Confidence and uncertainty

Confidence is high that cyber-specific activity prompted the outage because the university directly documented attempted unauthorized activity, network-edge detection, containment and precautionary shutdowns. Confidence is also high that the shutdown materially disrupted academic administration and student services because the university documented website unavailability, deadline changes, the delayed start of classes, phased account recovery and continuing financial-aid restoration.

The public record supports no known confidentiality impact because the university found no evidence of data access or exfiltration. That statement is an investigative finding rather than a final forensic conclusion. Ransomware and threat-actor attribution remain unresolved, and passphrase resets do not by themselves prove credential compromise.

Current status

The incident is presumed resolved. The university delayed the start of fall classes to Aug. 24 so essential systems could be restored, and classes then began. Financial-aid technology was still coming online Aug. 25, but the university’s current technology-alert page displayed ordinary planned maintenance when reviewed Aug. 31 rather than a continuing cyber-recovery disruption. No later source identified an ongoing outage, workaround or service delay. This is an analytic presumption based on resumed academic operations and the absence of contrary operational evidence, not a university-issued incident-wide all-clear.

Analytic gaps

The public record does not establish the exact time the activity began, its source or type, the initial access vector, targeted device or account, whether any non-core system was accessed, the reason for the passphrase reset, a complete inventory of systems still unavailable, forensic indicators, responsible party or full-restoration date.

Organizations involved

Impacted location

Sources

The University of Texas at San Antonio takes systems offline after intrusion attempt

We reported that UT San Antonio took systems offline after detecting attempted unauthorized activity, disrupting accounts, registration, payments and phone service before fall classes. The university reported no evidence of data access or exfiltration, while phones remained unavailable late Monday afternoon and no incident-specific final all-clear had been published.

UT San Antonio website access issue update

UT San Antonio said access to UTSA.edu was affected, that it was working to restore the website and that UT San Antonio Today at news.utsa.edu remained available for university news and information.

UT San Antonio systems go offline after attempted cybersecurity breach

Texas Public Radio republished the San Antonio Report account describing disrupted university accounts and services, deadline changes, phone-system downtime and the university’s ongoing investigation.

UT San Antonio systems go offline after attempted cybersecurity breach

The report documented little or no access to university accounts and systems, problems reaching payments, registration and course information, a payment-deadline extension, waitlist restoration, phone unavailability and planned passphrase resets.

As fall semester kicks off, assistance is available to those needing help resetting their passphrases

The university’s evolving update documents the Aug. 17 unauthorized-activity disclosure, the delay of fall classes from Aug. 19 to Aug. 24, phased restoration of email and system access, student passphrase resets and extended access support through Aug. 25.

Class Schedule

An Aug. 25 update said financial-aid refunds would resume as necessary technology systems came online. One Stop phone lines and student passphrase resets were available, and extended access support continued.

Campuses and Locations

The university lists its Main, Downtown and Southwest campuses and related academic locations in San Antonio separately from its Health Science Center campus.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

The University of Texas at San Antonio official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

UT San Antonio technology alerts

As reviewed Aug. 31, the university’s current technology-alert page listed ordinary planned maintenance, including fiscal year-end Banner processing, and did not identify a continuing cyber-recovery outage or workaround.

See something that needs correction?

Signed-in members can report an error, update, or missing source.