Back-to-school cyberattack locks 42K students out of Texas university systems, classes now delayed
UT San Antonio registration, payments, and phone systems are still down as school bumps first day of classes until next week.

Image by University of Texas at San Antonio (UTSA)
- Hackers breached University of Texas at San Antonio over the weekend, forcing critical university systems offline just days before classes begin.
- School officials have decided to postpone the start of fall classes until Monday, August 24th, as systems remain distrupted.
- All students,faculty, and staff will be required to reset their passwords as the university works to restore systems.
- UT San Antonio says it has found no evidence of data theft so far, but the investigation remains ongoing.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The University of Texas at San Antonio (UTSA) was hit by hackers over the weekend, causing major IT disruptions across campus for the 42,000 students preparing to return to class starting Wednesday.
First day of classes delayed, systems remain offline
Updated August 19th: UT San Antonio announced late Tuesday it has officially delayed the start of the fall semester until Monday, August 24th, as most systems remain offline.
Classes were originally scheduled to begin Wednesday, August 19th, but university officials say the delay will give teams more time to restore "myUTSA Account" access, .edu email, payment systems, and other essential services before students return.
“We are making this decision to ensure the university systems, technology and services our students, faculty and staff rely upon are operating optimally as we begin the semester,”UT San Antonio President Taylor Eighmy said.
“Starting classes on Monday gives our teams the necessary time to restore services carefully and position our university community for a strong start,” Eighmy added.
The school says university operations will continue as scheduled, with faculty and staff maintaining normal work schedules.
Registration also remains open, while the fall semester payment deadline has been extended until Friday, August 21, as of now.
Back-to-school cyberattack
The Texas university first became aware of what it describes as “unauthorized activity against university technology systems,” forcing its security teams to shut down .edu systems and other academic-related services while it investigates the incident.
“The activity was detected at the edge of our network, before it reached core systems, and University Technology Solutions (UTS), working with expert partners, took immediate action to contain it and protect the campus’ entire technology environment,”Andrea Marks, Senior Executive Vice President of Enterprise Operations and Strategy and Chief Operating Officer, and Michael Schnabel, Chief Technology Officer, said in a statement issued on Monday at 6:00 a.m. local time.
According to officials, registration, payment services, and university phone systems remain disrupted, with the fall 2026 semester set to begin in just two days.
Some students reported library research systems were also offline.
Students scramble as data questions linger
The university says it has "no evidence" that any student, faculty, or university data was "accessed or exfiltrated," although the investigation remains ongoing, leaving questions about the scope of the breach.
“There’s almost no worse week for a university technology outage than the start of a new school year," says Ross Filipek, CISO at Corsica Technologies, adding that taking major systems offline “creates immediate pressure to get everything running again.”
“Thousands of students are registering for classes, paying tuition, accessing course information, and trying to resolve last-minute issues,”Filipek says.
The school has been scrambling to accommodate the influx of students, announcing on Monday that it is extending its payment deadline – normally due the day classes begin – to 5:00 p.m. Friday while crews work to restore access.
Class waitlists were also being restored, and registration for the semester will remain open, it added.
"How are we expected to pay tuition if it's not up by tomorrow?” one student asked, echoing the sentiment of many others on social media.
Other frustrated students went online hoping to find out more information, reporting they were unable to log into their student accounts and email.
"Two days until classes and I need to go to the bookstore, but since I use financial assistance it goes through the university system so I cannot get books or materials. I keep checking to see if it’s up. Praying. It’s my last semester and I can’t have anything mess it up," one senior wrote on Facebook.
Another student was already worried about falling behind in coursework. "The website is still down! I never got to review my syllabus’s…," they said.
Mass password reset coming
“As part of our ongoing response, we have proactively taken some systems and services offline so our teams can thoroughly evaluate the environment, reinforce safeguards, and ensure appropriate protections are in place before returning services to normal operations," UTSA communicated to parents and students.
As part of those safeguards, all students, faculty, and staff will be required to reset their passwords – or “passphrases” as they are referred to on campus.
Officials say the reset is part of the school's recovery process, but have told all users to wait for further instructions from the university on how to do so.
The school originally said users should expect specific instructions on Tuesday, but that guidance now appears to be delayed as well.
Phone systems were also expected to be back up and running by Tuesday, although service is reportedly still offline.
Attackers strike when downtime hurts most
Meanwhile, the university has not disclosed who may be behind the attack, whether ransomware was involved, or how its systems were breached.
Filipek also questions whether the timing of the attack was intentional.
The UTSA cyberattack comes just months after a massive breach of e-learning platform Canvas by Instructure, which took place during finals week this past spring and impacted tens of thousands of students worldwide.
The attack, carried out by the ShinyHunters extortion group, forced schools across the US to cancel exams, with the company eventually forking over a $15 million ransom to bring systems back online and protect millions of student files.
“Attackers understand that disruption carries more weight when an organization is already operating at maximum capacity. Universities are no different from hospitals or retailers in that respect. The more painful downtime becomes, the more leverage an attacker potentially gains,” Filipek says.
So far, no threat actor has come forward to claim responsibility for the attack.