Download the Full Threat Brief
Get the complete 2026 Higher Education Cyber Threat Brief — 35 verified sources, 8-framework compliance crosswalk, 12-item action checklist. Delivered to your inbox.
Executive Summary
The highest-value, lowest-defended data portfolio in Texas
1,000+
U.S. higher education institutions hit by ransomware or breach in 2024
$3.80M
Education sector average breach cost 2025 (IBM) — rising against global trend
207 days
Average dwell time before breach detection in education
8
Compliance frameworks converging on TX higher ed
Texas universities and community colleges hold research intellectual property from DoD grants worth millions, student PII across entire enrollment histories, financial aid data including SSNs and tax records, and PHI from medical and nursing schools. They operate this on networks built for open academic collaboration — not security. TTUHSC lost 1.4 million patient records to Interlock ransomware in 2024. Columbia University disclosed 870,000 records compromised in May 2025. The education sector's average breach cost reached $3.80 million in 2025.
Threat Landscape — 2024–2026 Incidents
10 documented incidents and campaigns affecting Texas higher education
September 2024 — Texas
TTUHSC — 1.4M Records
Unauthorized access September 17–29, 2024 — 12-day dwell window. Interlock ransomware claimed 3.2TB exfiltrated including medical records, administrative documents, and patient financial information. Post-breach remediation exceeded $7M. HIPAA OCR investigation of entire TTUHSC health system triggered.
May 2023–Ongoing — National
MOVEit / Clop Campaign
Clop ransomware exploited CVE-2023-34362 affecting 3,000+ U.S. entities. Colorado State University, St. Joseph's College (126,580 individuals), Chicago Public Schools (700,000+ students) among confirmed higher-ed victims. Campaign continued into 2025 via Cleo file transfer exploitation.
May 2025 — National
Columbia University — 870K Records
Attackers accessed 460GB of data including admissions, financial aid, and academic records. SSNs, financial details, and research data compromised. Exposed SSNs are now fueling fraudulent FAFSA applications using the stolen student identities.
December 2024 — National
PowerSchool — 60M Student Platform
Breach via compromised technical support subcontractor credentials. Student names, addresses, SSNs, medical information, and academic records exfiltrated. Multiple Texas school districts and community colleges use PowerSchool — follow-on attacks using exfiltrated data ongoing through 2025.
2024–2025 — Education Sector
Interlock — 850% Surge
From 2 confirmed education attacks in 2024 to 17 confirmed attacks in 2025 — an 850% increase. Targets via compromised VPN credentials, edge device vulnerabilities, and phishing of faculty and administrative accounts.
2024–Ongoing — Texas
VOLT TYPHOON — Research Targeting
CISA AA24-038B confirmed China MSS-affiliated VOLT TYPHOON pre-positioned in U.S. critical infrastructure including university research networks. Texas universities with defense research programs (UT-Austin, Texas A&M, Tech, UH) in scope. Slow-burn credential harvesting on university SSO systems.
BEC attacks on Texas universities: $3.05 billion in total BEC losses (FBI IC3 2025). Universities are high-value targets — tuition refunds, vendor payments, construction invoices, alumni donations. Athletics departments, construction projects, and alumni relations offices are the highest-risk units. Southern Oregon University lost $1.9M to a single BEC attack in 2024.
FAFSA ghost student fraud: Fraud rings using AI-generated synthetic identities to create fake enrollments and collect federal Pell Grants. California community colleges reported 31–34% fraudulent applications in 2025. Federal government has prevented over $1 billion in student aid fraud since January 2025. Community colleges with open enrollment are primary targets.
Regulatory Stack — 8 Compliance Frameworks
FERPA + GLBA Safeguards + HIPAA + CMMC L2 + TX DIR + TX SB 820 + TX HB 300 + PCI DSS
| Framework | Scope | Key Penalty | Status |
| FERPA | All institutions receiving federal education funding | Loss of all federal funding | Active |
| GLBA Safeguards (2023) | Financial aid offices at any institution in federal student loan programs | $50,120/violation/day | Enforced |
| CMMC Level 2 | Research departments with DoD CUI | Contract termination | Nov 2026 |
| HIPAA Security Rule | Medical/dental/nursing schools, teaching hospitals, student health | $1.5M/category/year | Active |
| TX DIR / TAC 202 | All TX public universities and higher-ed institutions | DIR enforcement | Active |
| TX SB 820 | Any breach of TX resident PII | $100/day/resident + AG action | Active |
| TX HB 300 | Health data — stricter than federal HIPAA | $1.5M/year/category | Active |
| PCI DSS v4.0.1 | Tuition payments, bookstore POS, housing deposits, campus cards | $5K–$100K/month | Mandatory |
Primary Attack Vectors
Vector #1
Faculty & Admin Phishing
97% of UK higher-ed institutions experienced a phishing breach in the past year. AI-generated phishing emails surged 1,265% post-GenAI. MFA bypass via push bombing and OAuth consent phishing are dominant 2025–2026 tactics.
Vector #2
Exposed Research Environments
Open Wi-Fi for visiting scholars, VPN access for remote labs, legacy instruments with network interfaces. CUI on DoD grants sits in research environments rarely segmented from general university networks — exactly the surface VOLT TYPHOON targets.
Vector #3
Shadow IT in Academic Departments
Academic departments run their own software, cloud accounts, and vendor relationships outside IT visibility. Only 22% of institutions regularly monitor third-party vendor compliance. EdTech vendors are the #1 FERPA and GLBA breach vector.
Vector #4
Athletics & Alumni BEC
Athletics departments handle high-value wire transfers with less rigorous IT security. Alumni databases contain decades of SSNs and donation history. The Texas A&M system orbit has been specifically targeted in construction and athletics BEC schemes.
The 207-Day Problem — Applied to Higher Education
Every day of undetected access compounds the damage exponentially
$1,900
Additional breach cost per day of dwell time (IBM 2025)
$393K
Incremental cost before detection at 207-day average
48 hrs
CoreRecon SOC reduces dwell time from 207 days to under 48 hours
$1.9M+
Per-incident savings with 24/7 SOC coverage (IBM 2025)
Research data exfiltration: A nation-state actor entering a university research network in September has access through the entire academic year. VOLT TYPHOON-style actors use slow-burn persistence — by detection, the attacker has exfiltrated years of CUI research data from DoD grants.
FERPA funding loss risk: OCR investigations triggered by FERPA breaches take 12–24 months and can result in loss of all federal funding. For a mid-size Texas university, that is $50M+ in annual Title IV aid exposure.
Compliance Cost Math
What a breach actually costs a Texas university
| Exposure Category | Estimated Impact |
| GLBA Safeguards violations | $500K–$2M in combined penalties, remediation, and funding risk. Title IV funding disabled by DE Cybersecurity Team. |
| FERPA funding loss (20K students) | $50M+ annual Title IV aid at risk. $500K–$2M OCR investigation costs. 3–5 year corrective action plan. |
| CMMC contract loss ($15M DoD awards) | $5M–$20M/year at risk. $50K–$150K C3PAO assessment. $200K–$800K POA&M remediation per department. |
| HIPAA OCR settlement | Average $1.9M university settlement. TX HB 300 adds $1.5M/year/category. Notification costs $390K average. |
| Combined TX university breach | $8M–$15M for FERPA+GLBA+HIPAA. With research loss: $20M+ total impact. |
The CoreRecon Approach
The only security posture designed for the higher education attack surface
SOC
24/7 SOC — 30-Min IR SLA
Named analyst response within 30 minutes on confirmed breach. Continuous behavioral analytics across university networks, research enclaves, financial aid, and SIS platforms. Dwell time from 207 days to under 48 hours.
Architecture
Multi-Tenant Academic Visibility
Department-level visibility and alerting. Each college, research center, and admin unit operates independently — CoreRecon maps to the decentralized reality of university IT.
Compliance
GLBA Safeguards Mapping
Covers all 9 required GLBA elements: QI designation, risk assessment, MFA, encryption, data inventory, change management, continuous monitoring, secure disposal, and service provider oversight. Annual board report included.
Research
CMMC L2 — Research Office
Work directly with sponsored programs administrators. CUI scoping, SPRS gap analysis (110 NIST 800-171 controls), POA&M management, SSP documentation, and C3PAO-ready artifact packages. SDVOSB certified.
Pricing: $89–$129/endpoint/month. No enterprise contracts. No six-figure minimums. No RFP required for initial engagement.
30/60/90 Day Action Checklist
12 items. Start today.
- Days 1–30: Identify every system handling FERPA, GLBA, HIPAA, and CUI data. Document your data inventory — first requirement under GLBA Safeguards Rule.
- Days 1–30: Confirm your SPRS score. If negative with active DoD awards, contact Sponsored Programs immediately — you are already non-compliant with DFARS 7012.
- Days 1–30: Audit MFA on SIS (Banner/Workday/PeopleSoft), financial aid, VPN, and email. Deploy MFA on all before Day 30.
- Days 1–30: Verify 24/7 monitoring on network perimeter and research enclaves. If SOC coverage ends at 5pm — confirmed gap.
- Days 1–30: Review incident response plan for SIS ransomware scenario. When was it last tested? Who is the first call?
- Days 31–60: Conduct annual GLBA Safeguards Rule risk assessment. If none since June 2023, you are already in violation.
- Days 31–60: Designate or confirm GLBA Qualified Individual. If held by IT director with no dedicated security focus — immediate regulatory gap.
- Days 31–60: Tabletop exercise: registrar, financial aid, sponsored programs, legal, communications, president's office. Document the response timeline.
- Days 31–60: Segment research enclaves handling DoD CUI from general university networks. NIST 800-171 Control 3.13.5.
- Days 31–60: Vendor risk assessment on top 5 third-party systems. GLBA §314.4(f)(3) makes you responsible for vendor security.
- Days 61–90: Complete SPRS self-assessment for all research departments handling CUI. Build POA&M for any scoring below 110.
- Days 61–90: Initiate CMMC Level 2 gap analysis. November 2026 C3PAO deadline means formal gap analysis needed by Q3 2026.
Protect Your Institution's Data
30-minute security posture assessment for Texas universities and community colleges. We identify your FERPA, GLBA, HIPAA, and CMMC exposure — the gaps between your current protection and what a breach-ready defense looks like. No obligation.