Texas Higher Education — Cyber Threat Brief 2026

The University Is the Target

Research IP from DoD grants. Student PII across entire enrollment histories. Financial aid data including SSNs and tax records. PHI from medical schools. 1,000+ U.S. higher education institutions were hit in 2024. FERPA, GLBA Safeguards Rule, HIPAA, CMMC L2, TX SB 820, PCI DSS, and Texas DIR controls — eight compliance frameworks converge on a single attack surface.

1.4M
TTUHSC patient records — Interlock 2024
$3.80M
Avg education sector breach cost (IBM 2025)
35
Verified sources in this brief
Largest TX Higher Ed Breach
TTUHSC — 1.4M Records
Interlock ransomware — Sept 2024 — 3.2TB exfiltrated
Ransomware Volume
251 Attacks in 2025
3.96M records breached — 23% YoY increase
CMMC L2 Deadline
November 10, 2026
C3PAO assessment required for DoD research contracts
FAFSA Fraud Scale
$1B+ Prevented
Ghost student fraud since Jan 2025 — losses continue

Download the Full Threat Brief

Get the complete 2026 Higher Education Cyber Threat Brief — 35 verified sources, 8-framework compliance crosswalk, 12-item action checklist. Delivered to your inbox.

Brief sent to your email. Browse more resources →

Executive Summary

The highest-value, lowest-defended data portfolio in Texas

1,000+
U.S. higher education institutions hit by ransomware or breach in 2024
$3.80M
Education sector average breach cost 2025 (IBM) — rising against global trend
207 days
Average dwell time before breach detection in education
8
Compliance frameworks converging on TX higher ed

Texas universities and community colleges hold research intellectual property from DoD grants worth millions, student PII across entire enrollment histories, financial aid data including SSNs and tax records, and PHI from medical and nursing schools. They operate this on networks built for open academic collaboration — not security. TTUHSC lost 1.4 million patient records to Interlock ransomware in 2024. Columbia University disclosed 870,000 records compromised in May 2025. The education sector's average breach cost reached $3.80 million in 2025.

Threat Landscape — 2024–2026 Incidents

10 documented incidents and campaigns affecting Texas higher education

September 2024 — Texas
TTUHSC — 1.4M Records
Unauthorized access September 17–29, 2024 — 12-day dwell window. Interlock ransomware claimed 3.2TB exfiltrated including medical records, administrative documents, and patient financial information. Post-breach remediation exceeded $7M. HIPAA OCR investigation of entire TTUHSC health system triggered.
May 2023–Ongoing — National
MOVEit / Clop Campaign
Clop ransomware exploited CVE-2023-34362 affecting 3,000+ U.S. entities. Colorado State University, St. Joseph's College (126,580 individuals), Chicago Public Schools (700,000+ students) among confirmed higher-ed victims. Campaign continued into 2025 via Cleo file transfer exploitation.
May 2025 — National
Columbia University — 870K Records
Attackers accessed 460GB of data including admissions, financial aid, and academic records. SSNs, financial details, and research data compromised. Exposed SSNs are now fueling fraudulent FAFSA applications using the stolen student identities.
December 2024 — National
PowerSchool — 60M Student Platform
Breach via compromised technical support subcontractor credentials. Student names, addresses, SSNs, medical information, and academic records exfiltrated. Multiple Texas school districts and community colleges use PowerSchool — follow-on attacks using exfiltrated data ongoing through 2025.
2024–2025 — Education Sector
Interlock — 850% Surge
From 2 confirmed education attacks in 2024 to 17 confirmed attacks in 2025 — an 850% increase. Targets via compromised VPN credentials, edge device vulnerabilities, and phishing of faculty and administrative accounts.
2024–Ongoing — Texas
VOLT TYPHOON — Research Targeting
CISA AA24-038B confirmed China MSS-affiliated VOLT TYPHOON pre-positioned in U.S. critical infrastructure including university research networks. Texas universities with defense research programs (UT-Austin, Texas A&M, Tech, UH) in scope. Slow-burn credential harvesting on university SSO systems.

BEC attacks on Texas universities: $3.05 billion in total BEC losses (FBI IC3 2025). Universities are high-value targets — tuition refunds, vendor payments, construction invoices, alumni donations. Athletics departments, construction projects, and alumni relations offices are the highest-risk units. Southern Oregon University lost $1.9M to a single BEC attack in 2024.

FAFSA ghost student fraud: Fraud rings using AI-generated synthetic identities to create fake enrollments and collect federal Pell Grants. California community colleges reported 31–34% fraudulent applications in 2025. Federal government has prevented over $1 billion in student aid fraud since January 2025. Community colleges with open enrollment are primary targets.

Regulatory Stack — 8 Compliance Frameworks

FERPA + GLBA Safeguards + HIPAA + CMMC L2 + TX DIR + TX SB 820 + TX HB 300 + PCI DSS

FrameworkScopeKey PenaltyStatus
FERPAAll institutions receiving federal education fundingLoss of all federal fundingActive
GLBA Safeguards (2023)Financial aid offices at any institution in federal student loan programs$50,120/violation/dayEnforced
CMMC Level 2Research departments with DoD CUIContract terminationNov 2026
HIPAA Security RuleMedical/dental/nursing schools, teaching hospitals, student health$1.5M/category/yearActive
TX DIR / TAC 202All TX public universities and higher-ed institutionsDIR enforcementActive
TX SB 820Any breach of TX resident PII$100/day/resident + AG actionActive
TX HB 300Health data — stricter than federal HIPAA$1.5M/year/categoryActive
PCI DSS v4.0.1Tuition payments, bookstore POS, housing deposits, campus cards$5K–$100K/monthMandatory

Primary Attack Vectors

Vector #1
Faculty & Admin Phishing
97% of UK higher-ed institutions experienced a phishing breach in the past year. AI-generated phishing emails surged 1,265% post-GenAI. MFA bypass via push bombing and OAuth consent phishing are dominant 2025–2026 tactics.
Vector #2
Exposed Research Environments
Open Wi-Fi for visiting scholars, VPN access for remote labs, legacy instruments with network interfaces. CUI on DoD grants sits in research environments rarely segmented from general university networks — exactly the surface VOLT TYPHOON targets.
Vector #3
Shadow IT in Academic Departments
Academic departments run their own software, cloud accounts, and vendor relationships outside IT visibility. Only 22% of institutions regularly monitor third-party vendor compliance. EdTech vendors are the #1 FERPA and GLBA breach vector.
Vector #4
Athletics & Alumni BEC
Athletics departments handle high-value wire transfers with less rigorous IT security. Alumni databases contain decades of SSNs and donation history. The Texas A&M system orbit has been specifically targeted in construction and athletics BEC schemes.

The 207-Day Problem — Applied to Higher Education

Every day of undetected access compounds the damage exponentially

$1,900
Additional breach cost per day of dwell time (IBM 2025)
$393K
Incremental cost before detection at 207-day average
48 hrs
CoreRecon SOC reduces dwell time from 207 days to under 48 hours
$1.9M+
Per-incident savings with 24/7 SOC coverage (IBM 2025)

Research data exfiltration: A nation-state actor entering a university research network in September has access through the entire academic year. VOLT TYPHOON-style actors use slow-burn persistence — by detection, the attacker has exfiltrated years of CUI research data from DoD grants.

FERPA funding loss risk: OCR investigations triggered by FERPA breaches take 12–24 months and can result in loss of all federal funding. For a mid-size Texas university, that is $50M+ in annual Title IV aid exposure.

Compliance Cost Math

What a breach actually costs a Texas university

Exposure CategoryEstimated Impact
GLBA Safeguards violations$500K–$2M in combined penalties, remediation, and funding risk. Title IV funding disabled by DE Cybersecurity Team.
FERPA funding loss (20K students)$50M+ annual Title IV aid at risk. $500K–$2M OCR investigation costs. 3–5 year corrective action plan.
CMMC contract loss ($15M DoD awards)$5M–$20M/year at risk. $50K–$150K C3PAO assessment. $200K–$800K POA&M remediation per department.
HIPAA OCR settlementAverage $1.9M university settlement. TX HB 300 adds $1.5M/year/category. Notification costs $390K average.
Combined TX university breach$8M–$15M for FERPA+GLBA+HIPAA. With research loss: $20M+ total impact.

The CoreRecon Approach

The only security posture designed for the higher education attack surface

SOC
24/7 SOC — 30-Min IR SLA
Named analyst response within 30 minutes on confirmed breach. Continuous behavioral analytics across university networks, research enclaves, financial aid, and SIS platforms. Dwell time from 207 days to under 48 hours.
Architecture
Multi-Tenant Academic Visibility
Department-level visibility and alerting. Each college, research center, and admin unit operates independently — CoreRecon maps to the decentralized reality of university IT.
Compliance
GLBA Safeguards Mapping
Covers all 9 required GLBA elements: QI designation, risk assessment, MFA, encryption, data inventory, change management, continuous monitoring, secure disposal, and service provider oversight. Annual board report included.
Research
CMMC L2 — Research Office
Work directly with sponsored programs administrators. CUI scoping, SPRS gap analysis (110 NIST 800-171 controls), POA&M management, SSP documentation, and C3PAO-ready artifact packages. SDVOSB certified.

Pricing: $89–$129/endpoint/month. No enterprise contracts. No six-figure minimums. No RFP required for initial engagement.

30/60/90 Day Action Checklist

12 items. Start today.

Protect Your Institution's Data

30-minute security posture assessment for Texas universities and community colleges. We identify your FERPA, GLBA, HIPAA, and CMMC exposure — the gaps between your current protection and what a breach-ready defense looks like. No obligation.