The University of Texas at San Antonio

Classes resumed Aug. 24, major services returned and the current technology-alert page showed ordinary planned maintenance rather than continuing incident recovery. The incident is presumed resolved, although the university has not issued an incident-wide all-clear.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.
The organization could not process, receive, issue, reconcile, or record payments normally.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
A public-facing website was unavailable, disabled, or inaccessible.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
UT San Antonio first acknowledged Aug. 15 that UTSA.edu was inaccessible and redirected users to UT San Antonio Today while restoration work continued. On Aug. 17, the university said it had detected attempted unauthorized activity at the edge of its academic-campus network over the weekend. University Technology Solutions and outside specialists contained the activity before it reached core systems, then proactively took some systems and services offline for evaluation and additional safeguards. The university’s description of unauthorized activity provides concrete evidence of cyber involvement even though the public record does not establish a successful intrusion into core systems.
The university said its response was effective and that the continuing investigation found no evidence that university data was accessed or exfiltrated. No public source identified ransomware, malware, a ransom demand or a responsible party. Searches using the university’s name and utsa.edu found no stable ransomware or extortion victim claim.
The disruption affected UT San Antonio’s academic-campus technology environment, not the Health Science Center. It made the public website unavailable and disrupted university accounts, registration, payments, course information, waitlists and phone service immediately before the fall semester. The university extended payment and course-add deadlines, restored waitlist positioning and required university-wide passphrase resets.
On Aug. 18, the university delayed the first day of fall classes from Aug. 19 to Aug. 24 so teams could continue restoring connectivity, email and other essential services. On Aug. 20, it said more systems and services were returning each day and began phased student passphrase resets. Extended technology-access support continued through Aug. 25.
A One Stop update dated Aug. 25 said financial-aid refunds would resume as necessary technology systems came online. It also said phone lines were available and student passphrase resets could be completed, documenting substantial recovery but not full restoration.
UT San Antonio’s Aug. 15 public message described a website-access issue without cyber or security wording. Its Aug. 17 notice supplied the first identified affected-organization cyber characterization by describing attempted unauthorized activity at the network edge. No earlier credible external cyber characterization or stable actor claim was identified, so DysruptionHub assesses the disclosure sequence as organization-first.
Confidence is high that cyber-specific activity prompted the outage because the university directly documented attempted unauthorized activity, network-edge detection, containment and precautionary shutdowns. Confidence is also high that the shutdown materially disrupted academic administration and student services because the university documented website unavailability, deadline changes, the delayed start of classes, phased account recovery and continuing financial-aid restoration.
The public record supports no known confidentiality impact because the university found no evidence of data access or exfiltration. That statement is an investigative finding rather than a final forensic conclusion. Ransomware and threat-actor attribution remain unresolved, and passphrase resets do not by themselves prove credential compromise.
The incident is presumed resolved. The university delayed the start of fall classes to Aug. 24 so essential systems could be restored, and classes then began. Financial-aid technology was still coming online Aug. 25, but the university’s current technology-alert page displayed ordinary planned maintenance when reviewed Aug. 31 rather than a continuing cyber-recovery disruption. No later source identified an ongoing outage, workaround or service delay. This is an analytic presumption based on resumed academic operations and the absence of contrary operational evidence, not a university-issued incident-wide all-clear.
The public record does not establish the exact time the activity began, its source or type, the initial access vector, targeted device or account, whether any non-core system was accessed, the reason for the passphrase reset, a complete inventory of systems still unavailable, forensic indicators, responsible party or full-restoration date.

We reported that UT San Antonio took systems offline after detecting attempted unauthorized activity, disrupting accounts, registration, payments and phone service before fall classes. The university reported no evidence of data access or exfiltration, while phones remained unavailable late Monday afternoon and no incident-specific final all-clear had been published.
UT San Antonio said access to UTSA.edu was affected, that it was working to restore the website and that UT San Antonio Today at news.utsa.edu remained available for university news and information.
Texas Public Radio republished the San Antonio Report account describing disrupted university accounts and services, deadline changes, phone-system downtime and the university’s ongoing investigation.
The report documented little or no access to university accounts and systems, problems reaching payments, registration and course information, a payment-deadline extension, waitlist restoration, phone unavailability and planned passphrase resets.
The university’s evolving update documents the Aug. 17 unauthorized-activity disclosure, the delay of fall classes from Aug. 19 to Aug. 24, phased restoration of email and system access, student passphrase resets and extended access support through Aug. 25.
An Aug. 25 update said financial-aid refunds would resume as necessary technology systems came online. One Stop phone lines and student passphrase resets were available, and extended access support continued.
The university lists its Main, Downtown and Southwest campuses and related academic locations in San Antonio separately from its Health Science Center campus.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
As reviewed Aug. 31, the university’s current technology-alert page listed ordinary planned maintenance, including fiscal year-end Banner processing, and did not identify a continuing cyber-recovery outage or workaround.
Signed-in members can report an error, update, or missing source.