"attempted unauthorized activity" at the edge of its network, before reaching core systems, the university said in a statement released on August 17.
University leaders’ August 17 statement
University of Texas San Antonio leaders disclosed on August 17 that IT systems had been taken offline after detecting what they described as “attempted unauthorized activity” at the edge of the campus network. The statement said University Technology Solutions (UTS) acted with expert partners to contain the activity and took some systems offline to allow “a thorough evaluation of the environment” and to determine whether “additional protections need to be implemented.”
The university said its response “has been effective” and that, so far, “there has been no evidence that data was accessed or exfiltrated as a result of the unauthorized activity.” Leaders acknowledged the operational cost of those defensive moves: the shutdown of IT systems was causing disruption ahead of the academic term, which was scheduled to begin on August 19.
Actions by University Technology Solutions and partners
The statement names University Technology Solutions as the operational unit that took steps with outside experts to contain the incident. Those containment actions included taking some systems offline to allow for an evaluation of the environment and an assessment of whether “additional protections need to be implemented.”
UTS framed the shutdown as a deliberate trade-off: systems were placed offline to limit risk while incident responders reviewed the campus environment. The university said that these measures were intended to ensure the technology environment would be “both available and secure as we begin the new academic year.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOperational impacts: registration, tuition, phones and passphrases
The outage affected student-facing services most directly. The university confirmed that online registration and tuition payments were disrupted and that it had granted extensions for students to complete those processes. In a 12:30pm CST update on August 17, the university also reported that phone systems were not available but were expected to be restored later that day.
On social media, a further update posted to the university’s Facebook page at 5:30pm CST on August 17 said students, faculty and staff would be sent instructions to reset their passphrases on Tuesday, August 18. The university explicitly recognized the timing pressure: “With classes beginning this Wednesday, we recognize how important, reliable access to university systems and services is for our students, faculty and staff,” the statement read.
Expert commentary: Ross Filipek on timing, segmentation and resilience
Ross Filipek, CISO at Corsica Technologies, provided context in the university’s account. Filipek observed that educational institutions face heightened targeting at the start of the academic year because IT systems are under extra pressure from activities such as registration, tuition payments and course access. “Taking major systems offline at that moment creates immediate pressure to get everything running again,” he said, and noted that while intentional timing by attackers is “isn’t clear,” adversaries “understand that disruption carries more weight when an organization is already operating at maximum capacity.”
Filipek praised UT San Antonio for detecting and containing the incident early but emphasized the practical value of network segmentation: “Cyber resilience means being able to contain a threat without forcing the rest of the organization to choose between security and keeping the doors open.” He highlighted segmentation as a way to prevent containment measures from cascading into widespread operational outages.
What this means for students, IT teams, and university administrators
- For students: the immediate effect was operational — delayed ability to register for classes and to pay tuition on the expected schedule. The university granted extensions and planned a passphrase reset communication for August 18.
- For IT and security teams: the incident underscores the decision trade-offs between taking systems offline to contain activity and keeping services available during peak operational windows. The university’s use of incident partners and offline containment actions reflects a prioritization of assessment and protection over short-term availability.
- For university administrators: timing matters. With classes due to start August 19, the university acknowledged both the disruption and the need for controlled, deliberate remediation to ensure systems are secure as the term begins.
The university framed its response as effective and precautionary: containment first, evaluation second, service restoration alongside security measures. The lingering practical questions are narrow and concrete — when paused services will return to normal, whether passphrase resets will proceed as announced on August 18, and whether the post-incident evaluation will recommend additional protections to reduce the chance that containment itself causes widespread disruption in future start-of-term periods.




