Back-to-school cyberattack locks 42K students out of Texas university systems days before classes begin
UT San Antonio registration, payments, and phone systems are still down as thousands prepare to return to school Wednesday.

Image by University of Texas at San Antonio (UTSA)
- Hackers breached University of Texas at San Antonio over the weekend, forcing critical university systems offline just days before classes begin.
- All students,faculty, and staff will be required to reset their passwords as the university restores systems.
- UT San Antonio says it has found no evidence of data theft so far, but the investigation remains ongoing.
The University of Texas at San Antonio (UTSA) was hit by hackers over the weekend, causing major IT disruptions across campus for the 42,000 students preparing to return to class starting Wednesday.
The Texas university first became aware of what it describes as “unauthorized activity against university technology systems,” forcing its security teams to shut down .edu systems and other academic-related services while it investigates the incident.
“The activity was detected at the edge of our network, before it reached core systems, and University Technology Solutions (UTS), working with expert partners, took immediate action to contain it and protect the campus’ entire technology environment,”Andrea Marks, Senior Executive Vice President of Enterprise Operations and Strategy and Chief Operating Officer, and Michael Schnabel, Chief Technology Officer, said in a statement issued on Monday at 6:00 a.m. local time.
According to officials, registration, payment services, and university phone systems remain disrupted, with the fall 2026 semester set to begin in just two days.
Some students reported library research systems were also offline.
Despite the ongoing disruption, classes are still scheduled to kick off August 19th.
Back-to-school cyberattack
The university says it has "no evidence" that any student, faculty, or university data was "accessed or exfiltrated," although the investigation remains ongoing, leaving questions about the scope of the breach.
“There’s almost no worse week for a university technology outage than the start of a new school year," says Ross Filipek, CISO at Corsica Technologies, adding that taking major systems offline “creates immediate pressure to get everything running again.”
“Thousands of students are registering for classes, paying tuition, accessing course information, and trying to resolve last-minute issues,”Filipek says.
The school has been scrambling to accommodate the influx of students, announcing on Monday that it is extending its payment deadline – normally due the day classes begin – to 5:00 p.m. Friday while crews work to restore access.
Class waitlists were also being restored, and registration for the semester will remain open, it added.
"How are we expected to pay tuition if it's not up by tomorrow?” one student asked, echoing the sentiment of many others on social media.
Other frustrated students went online hoping to find out more information, reporting they were unable to log into their student accounts and email.
"Two days until classes and I need to go to the bookstore, but since I use financial assistance it goes through the university system so I cannot get books or materials. I keep checking to see if it’s up. Praying. It’s my last semester and I can’t have anything mess it up," one senior wrote on Facebook.
Another student was already worried about falling behind in coursework. "The website is still down! I never got to review my syllabus’s…," they said.
Mass password reset coming
“As part of our ongoing response, we have proactively taken some systems and services offline so our teams can thoroughly evaluate the environment, reinforce safeguards, and ensure appropriate protections are in place before returning services to normal operations," UTSA communicated to parents and students.
As part of those safeguards, all students, faculty, and staff will be required to reset their passwords – or “passphrases” as they are referred to on campus.
Officials say the reset is part of the school's recovery process and have instructed all users to wait until Tuesday for specific instructions from the university on how to do so.
Phone systems are also expected to be back up and running by Tuesday.
Attackers strike when downtime hurts most
Meanwhile, the university has not disclosed who may be behind the attack, whether ransomware was involved, or how its systems were breached.
Filipek also questions whether the timing of the attack was intentional.
The UTSA cyberattack comes just months after a massive breach of e-learning platform Canvas by Instructure, which took place during finals week this past spring and impacted tens of thousands of students worldwide.
The attack, carried out by the ShinyHunters extortion group, forced schools across the US to cancel exams, with the company eventually forking over a $15 million ransom to bring systems back online and protect millions of student files.
“Attackers understand that disruption carries more weight when an organization is already operating at maximum capacity. Universities are no different from hospitals or retailers in that respect. The more painful downtime becomes, the more leverage an attacker potentially gains,” Filipek says.