One of the largest universities in Texas just pushed the first day of its fall semester back three days because of an attempted cyberattack. The UTSA cyberattack attempt was detected over the weekend of August 15, the university took systems offline to contain it, and on August 18 President Taylor Eighmy announced classes would now start Monday, August 24.
Here is the part worth sitting with. UTSA stopped the attack. The investigation so far has found no evidence that any data was accessed or stolen. And it still cost the university phone service, email, password resets, payment processing, and the first three days of a semester. That math applies to your business too.
What happened at UTSA
Over the weekend, UTSA’s security team identified attempted unauthorized activity targeting university technology systems on its academic campus. In a joint statement, Chief Operating Officer Andrea Marks and Chief Technology Officer Michael Schnabel said the activity “was detected at the edge of our network, before it reached core systems.” University Technology Solutions, working with outside incident response partners, moved immediately to contain it.
Containment came with a deliberate cost. The university chose to take systems and services offline so its teams could evaluate the environment and reinforce safeguards before bringing anything back. The ripple effects piled up fast:
- Campus phone systems went down on August 17
- The password reset system backed up on August 18
- The tuition payment deadline moved to August 21, then was extended again to August 24 as restoration continued
- Course waitlists were paused and rebuilt in their original order
- The first day of classes moved from midweek to Monday, August 24
KSAT reported that the university does not believe any data was accessed or stolen, and UTSA’s own updates say the ongoing investigation has found no evidence of exfiltration. The delay, per Eighmy’s message to campus, exists so IT teams can restore connectivity, email, and other services carefully instead of rushing them back online.
Update, August 26: classes began Monday, August 24 on the revised schedule, and the recovery ran well past the first headlines. UTSA put its entire campus through a passphrase reset in scheduled waves over three days, grouped by last name, with anyone who reset early required to reset again once the new process was in place. In-person tech support stayed extended through at least August 25, and the university confirmed the academic calendar beyond the first week, including fall break and the end of the semester, was not affected. As of the university’s public updates, the finding stands: no evidence that data was accessed or stolen.
Why this was a win, not a breach
It sounds strange to call a semester delay a success story. It is one anyway.
The attack was caught at the network edge before it touched core systems. That means monitoring was in place, someone was watching on a weekend, and detection happened in hours rather than months. In many real breaches, attackers sit inside a network for weeks before anyone notices. UTSA’s team saw the attempt at the perimeter and shut the door.
Then they did the harder thing: they accepted downtime on purpose. Taking your own systems offline days before tens of thousands of students show up for classes is a painful call. It is also the right one. An organization that would rather limp along connected than disconnect and verify is an organization that eventually gets breached for real.
One more thing worth noting. This happened at a university with its own College of AI, Cyber and Computing, in a city that is a major cybersecurity hub. Attackers targeted them anyway. They do not skip Central Texas organizations because they are smaller or less famous. Smaller usually just means softer.
What the UTSA cyberattack cost, even as a win
Run the same timeline against your own operation. Phones down for a day. Password resets stalled. Payment processing paused. Core work delayed three days while your systems get checked and restored.
For a 20-person business, that is payroll spent on people who cannot work, jobs that slip, invoices that do not go out, and customers calling a line nobody can answer. And that is the good outcome, the one where the attack never got in. A business with no monitoring, no response plan, and untested backups does not measure that same event in days. It measures it in weeks, and sometimes in whether the business survives at all.
What your business can copy from UTSA’s playbook
Watch the edge, around the clock. This attempt was identified over a weekend, which is when most attacks land, precisely because nobody is at a desk. If your firewall logs and endpoints are only reviewed during business hours, your detection window is a coin flip. This is the core of what 24/7 managed cybersecurity exists to solve.
Decide in advance who can pull the plug. Someone at UTSA had the authority to take systems offline without a week of meetings. Write that decision down now. Your incident response plan should name who isolates systems, who calls your insurer and attorney, and who talks to customers.
Rotate credentials after an incident, even a contained one. UTSA reset passphrases for every student, faculty member, and staff member on campus, despite finding no evidence anything was compromised. That is the correct instinct. Once an attacker has probed your network, you treat credentials as suspect and rotate them on a schedule you control. It closes the one door an investigation might miss.
Have backups you have actually restored. The confidence to take systems down comes from knowing you can bring them back. If your last restore test was never, you do not have a backup and recovery plan. You have a hope.
Communicate early and on a schedule. UTSA published updates daily, sometimes twice a day, including the unflattering ones about phone outages and password backlogs. Customers forgive downtime. They do not forgive silence.
If you run a Texas governmental entity such as an appraisal district, none of this is optional anyway. TAC 202 already expects documented incident response, and an event like this one is exactly the scenario your security program is supposed to be built for.
If you are not sure who would catch an attack against your network at 2 a.m. on a Saturday, that is the gap to close first. We will walk through your environment with you and show you where you stand. No pressure, no obligation.
Frequently asked questions
Last updated August 26, 2026, with restoration details from UTSA’s official updates page.
Sources:
UT San Antonio Today: official updates page on the technology incident and semester start
KENS 5: UT San Antonio delays start of fall semester by three days after ‘unauthorized activity’ detected
KSAT: UTSA takes some services offline after attempted cybersecurity breach
San Antonio Report: UT San Antonio’s systems go offline after attempted cyber breach