TMCnet News
Keeper Security Issues Cybersecurity Guidance for Education IT Teams As Students Return to CampusAI-powered phishing attacks, deepfake impersonations and a surge of unmanaged machine identities are turning the back-to-school rush into a security blind spot CHICAGO, Aug. 13, 2026 /PRNewswire/ -- Every fall, school districts and universities across the country race to onboard thousands of new students, faculty and staff, provisioning accounts, issuing credentials and connecting a wave of new devices to institutional networks. It is a moment of organized chaos, and cybercriminals know it. Now, with artificial intelligence supercharging phishing campaigns and a hidden layer of unmanaged machine identities quietly expanding the attack surface, Keeper Security, the leading provider of zero-trust and zero-knowledge identity security and Privileged Access Management (PAM), is providing guidance to education IT teams this back-to-school season. Keeper is sharing the top threats facing K-12 districts and higher education institutions this fall and the steps IT teams can take to protect their students and faculty before the semester begins.
The Threat Window Is Growing The education sector is one of the highest targeted industries for ransomware, credential theft and data breaches. Schools and universities present an appealing combination of high-value data, including student records, financial information and research, alongside chronically underfunded IT departments and an enormous, ever-rotating user base. Back-to-school season intensifies every one of these vulnerabilities. Bulk account creation, mass device enrollment and a surge of third-party application onboarding all happen simultaneously, creating a window of misconfiguration and exposure that attackers are primed to exploit. However, Keeper research finds only 14% of schools mandate security awareness training, and that lack of education shows, with nearly one in five students and parents reporting they reuse the same passwords across both personal and school accounts. AI has made cybersecurity threats significantly more dangerous. Phishing emails can now precisely mimic communications from financial aid offices, IT helpdesks or university leadership, with none of the red flags that once made them easy to spot. Deepfake voice and video attacks are putting convincing faces and voices behind those messages, making it harder for staff to trust what they see and hear. Keeper research found 52% of education leaders identify deepfake impersonation as a top concern, yet only 26% feel confident in their ability to recognize AI-enabled threats. And the barrier to entry for attackers has dropped dramatically: tools that once required real sophistication are now widely available, meaning credential attacks that previously targeted only the largest institutions can now be aimed at any school district or campus. Forty-one percent of institutions report that they have been targeted by AI-generated phishing attempts or misinformation campaigns. The Hidden Attack Surface: Non-Human Identities in EdTech While IT teams focus on securing human accounts, afar larger and largely invisible population of digital identities is growing unchecked across education environments: Non-Human Identities (NHIs). In a modern school district or university, NHIs are widespread and almost entirely unmanaged:
In most institutions, NHIs outnumber human users by a wide margin, yet few schools maintain an inventory of them. This causes the attack surface to explode, as each NHI represents a potential entry point for attackers. "The conversation about education cybersecurity has historically focused on human accounts: students, teachers and administrators," said Darren Guccione, CEO and Co-founder of Keeper Security. "But the real blind spot is the vast ecosystem of machine identities that power modern EdTech. Back-to-school is the right moment for education IT teams to take stock of every identity on their network, human and non-human alike." How Education IT Teams Can Reduce Their Risk For most institutions, the fundamentals are manageable: enforcing MFA, auditing privileged access and removing stale credentials before new users arrive. The harder challenge is building visibility and governance over the NHIs that power modern EdTech: service accounts, API tokens, machine certificates and AI agents that multiply with every new integration. Keeper recommends education IT teams take the following steps before the semester begins:
Keeper's zero-trust, zero-knowledge platform is purpose-built for these challenges, enabling institutions to discover, govern and automatically rotate credentials tied to human users and NHIs, including the AI agents and automated bots proliferating across EdTech environments. KeeperPAM also delivers the privileged access controls, session recording and audit trails institutions need to meet Family Educational Rights and Privacy Act (FERPA) and Children's Internet Protection Act (CIPA) requirements, and to ensure every identity on the network, human or non-human, is accounted for. For more information on how Keeper protects education institutions, visit keepersecurity.com. About Keeper Security Learn more: KeeperSecurity.com Media Contact
SOURCE Keeper Security
|
