The University of Texas at San Antonio took some systems offline after detecting attempted unauthorized activity against its technology systems, disrupting account access, registration, payments and phone service before fall classes.
The university said Monday the activity was identified over the weekend at the edge of its network and contained before it reached core systems. Its ongoing investigation had found no evidence that university data was accessed or exfiltrated.
The disruption affected only the academic campus, not the Health Science Center. University staff and outside specialists were examining systems and adding safeguards before restoring them.
Students, faculty and staff had little or no access to university accounts and systems, the San Antonio Report reported. Families also had trouble accessing payment, registration and course information days before classes begin Wednesday.
UT San Antonio extended its payment deadline to Friday, kept fall registration open and returned students to their original waitlist positions. Students could change their schedules once they regained account access.
The university also required faculty, staff and students to reset their account passphrases after receiving instructions. The university did not explain why it required the resets.
As of late Monday afternoon, phone service remained unavailable and the university had not published an incident-specific final all-clear. It expected phone service to return later Monday.
The disruption follows an Aug. 10 cybersecurity incident at Brazosport College in Lake Jackson, Texas, that limited enrollment services and delayed two fall terms as systems were restored in phases.
UT San Antonio has not identified the type of activity, how it began or who was responsible. Its latest notice did not list every service still offline or give a full restoration timeline. No public source reviewed identified ransomware, malware or a ransom demand.