The Mississippi Institutions of Higher Learning said Thursday that a network security incident disrupted its student financial aid office, though the state’s online aid application portal remained available.
IHL said it brought in external cybersecurity professionals to investigate whether confidential or sensitive data had been accessed or compromised. Officials had not reached a determination.
The Office of Student Financial Aid was the only operation IHL publicly identified as affected. Students could continue submitting applications through the Mississippi Aid Application, or MAAPP, portal.
IHL said no individual university had reported problems and identified only its central financial aid office as affected.

The notice did not explain how the office’s work was disrupted or whether employees had lost access to internal systems. The statement also did not say when the incident began or how it was detected.
“Our priority is to return our systems to full functionality as quickly as possible,” IHL said. The agency promised updates but did not provide a restoration timeline.
Based in Jackson, IHL is the state governing body for Mississippi’s eight public universities and administers statewide programs, including student financial aid. Its 12 trustees are appointed by the governor with state Senate approval.
MAAPP is used to apply for state aid available to students attending public and private colleges in Mississippi. State programs include grants, forgivable loans and loan-repayment assistance.
In 2025, a cyber incident at Louisiana’s student financial assistance office delayed state scholarship and START college-savings payments and temporarily closed its Baton Rouge office. LOSFA reopened Oct. 27 after START resumed full operations and outstanding deposits were processed. A later forensic review found the START program was not involved, although certain other LOSFA files were.
Officials did not identify the affected systems, how the incident began or whether malware was involved. No ransomware group or other threat actor had been tied to the incident, and IHL had not reported data theft.
“At this time, the investigation is in its earliest stage,” IHL said. The extent of any data exposure and the timetable for restoring remaining functions were unknown.
The organization did not respond to a request for comment at the time of publication.