San Antonio/ Crime & Emergencies

UTSA Systems Go Dark After Attempted Breach Days Before Fall Classes Begin

AI Assisted Icon
Published on August 17, 2026
UTSA Systems Go Dark After Attempted Breach Days Before Fall Classes BeginSource: Google Street View

Students, faculty and staff at the University of Texas at San Antonio spent the days before the start of the fall semester locked out of email, class registration tools and even the university's phone lines after officials detected unauthorized activity targeting the school's technology systems over the weekend. The disruption left many unable to pay tuition balances, swap classes, or pull up syllabi just as the academic calendar was set to kick into gear.

University officials say the trouble began on August 15, when unauthorized activity targeted UTSA's technology systems, according to San Antonio Report. The university's Technology Solutions team detected the activity at the edge of the network and took immediate action to contain it and protect the campus technology environment. As of the outlet's report, the ongoing investigation had not found evidence of a data breach, though the review continues.

The timing could hardly have been worse. UTSA was set to begin its fall 2026 academic year on August 19, and the outage left students and their families struggling to make payments, change classes, or access class syllabi in the days beforehand, per the same account. Phone systems were down as of Monday but were expected to be restored later that day, while university officials cut access to some online services as a precaution.

Deadlines Pushed Back, Waitlists Restored

To ease the crunch, university officials extended the deadline to pay balances or enroll in payment plans, moving it from August 19 to 5 p.m. on August 21. Registration for the fall semester remained open throughout the disruption, and officials also restored waitlist access for students trying to secure spots in classes, the report notes.

Andrea Marks, senior executive vice president of enterprise operations and strategy, and Michael Schnabel, the university's chief technology officer, are listed among the officials overseeing the response, according to the same report. Students, faculty and staff are expected to receive notices and instructions to reset their university account passwords, which UTSA refers to internally as passphrases. Technology Solutions has advised users to wait for that official communication before attempting to begin the reset process on their own.

For those who run into trouble completing a reset through the university's online self-service portal, UTSA directs users to its Tech Café support desk. The process requires previously registered secondary contact information, and unverified accounts require direct administrative assistance, according to the university.

A Pattern of Disruptions at a Cybersecurity Powerhouse

The attempted breach lands just three months after a separate, global cyberattack on the classroom platform Canvas disrupted finals week at UTSA and other San Antonio-area schools in May, when an extortion group claimed responsibility for breaching platform developer Instructure and stealing millions of records worldwide, forcing UTSA to reschedule exams. That earlier incident, paired with this month's network disruption, points to a recurring vulnerability at a school whose academic calendar keeps colliding with digital outages.

The irony is not lost on observers of UTSA's cybersecurity credentials. The university holds three Center of Academic Excellence designations from the National Security Agency and Department of Homeland Security, and it opened its $91.8 million San Pedro I facility in 2023 to house the School of Data Science and National Security Collaboration Center. UTSA doubled down on that investment with the mid-2026 completion of the $131 million San Pedro II building, a 180,000-square-foot facility built for its newly formed College of AI, Cyber and Computing.

San Antonio itself markets its regional identity around this expertise, branding itself Cyber City USA and hosting the headquarters of the state-funded Texas Cyber Command, established in 2025 to streamline threat intelligence and incident response across Texas agencies. Even so, higher education institutions worldwide have not been spared: global cyberattacks against universities rose 63% between late 2023 and late 2025, with reported data breaches in the sector surging 73% over the same span, according to Infosecurity Magazine.

Legal Stakes If Data Was Exposed

Under Texas Business and Commerce Code § 521.053, entities that maintain computerized sensitive personal data must notify affected individuals within 60 days of confirming a breach, and report the incident to the Texas Attorney General within 30 days if 250 or more Texas residents are impacted, according to Davis Wright Tremaine. Texas Senate Bill 768 tightened that Attorney General notification deadline from 60 days down to 30 days, effective September 2023. Since UTSA's investigation has not yet found evidence of a breach, those clocks have not started, but the outcome of the forensic review will determine whether they ever do.

The stakes of any future account lockout or system shutdown are magnified by UTSA's scale. The university recorded a historic enrollment of more than 38,200 students for the 2025-2026 academic year, marking three consecutive years of record fall growth, including a freshman class exceeding 7,100 students. That growth, combined with the September 2025 merger that folded UT Health San Antonio into UTSA to create a unified research university with an estimated $2.2 billion annual budget, has significantly expanded the digital footprint officials must now secure.

Regional history offers a cautionary tale about how costly these incidents can become. Judson ISD confirmed in August 2021 that it paid $547,045 in taxpayer funds to ransom hackers who had infiltrated its IT systems and threatened to release sensitive personal data, according to KSAT. At the time, Gregory White, director of UTSA's Center for Infrastructure Assurance and Security, noted that paying ransoms incentivizes future attacks. For now, UTSA says it will take additional steps to protect its accounts and systems as the semester gets underway, with the university's own investigation into this month's activity still ongoing.