As schools and universities prepare for the new academic year, the rapid onboarding of students, faculty and staff is creating a period of increased cybersecurity risk, according to Keeper Security.
The security provider is warning education IT teams that bulk account creation, mass device enrollment and the addition of third-party applications can create opportunities for attackers. The education sector faces significant risks from ransomware, credential theft and data breaches due to the volume of valuable information held by institutions and their large, constantly changing user populations.
Keeper said its research found that only 14% of schools mandate security awareness training. Nearly one in five students and parents also reported reusing the same passwords across personal and school accounts.
AI Raises the Threat Level
Artificial intelligence is adding another layer of risk as attackers use AI-generated phishing messages that can closely imitate communications from financial aid offices, IT helpdesks and university leadership.
Deepfake voice and video attacks can also make fraudulent communications more convincing. Keeper reported that 52% of education leaders identify deepfake impersonation as a top concern while only 26% feel confident in their ability to recognize AI-enabled threats. Forty-one percent of institutions reported being targeted by AI-generated phishing attempts or misinformation campaigns.
Non-Human Identities Create a Hidden Attack Surface
Keeper is also highlighting the growing number of non-human identities (NHIs) operating across education environments.
Service accounts can connect student information systems with learning management systems while API keys and integration tokens link third-party learning applications, digital textbooks, library databases and payment gateways to institutional databases.
Machine identities and digital certificates authenticate devices including campus Wi-Fi connections, smart boards, lab equipment, 3D printers and security cameras. Cloud-managed identities and workloads support automated data backups, research data pipelines and administrative reporting. AI agents and automated bots are also increasingly being used for applications such as admissions chatbots, helpdesk scripts and grading assistants.
Keeper said these identities are often unmanaged and may include credentials that are rarely rotated, orphaned tokens from previous integrations or certificates that are expired or misconfigured.
"The conversation about education cybersecurity has historically focused on human accounts: students, teachers and administrators," said Darren Guccione, CEO and Co-founder of Keeper Security. "But the real blind spot is the vast ecosystem of machine identities that power modern EdTech. Back-to-school is the right moment for education IT teams to take stock of every identity on their network, human and non-human alike."
Recommended Security Measures
Keeper recommends that education IT teams enforce multifactor authentication across faculty, staff and student accounts before onboarding new users. The company also recommends deploying an enterprise password manager, auditing privileged access and removing access associated with departed employees, expired service accounts and unused applications.
Other recommendations include building an inventory of non-human identities, establishing credential rotation policies for machine identities and updating phishing awareness training to account for AI-generated messages.
Keeper said its zero-trust, zero-knowledge platform is designed to help institutions discover, govern and automatically rotate credentials associated with human users and NHIs. Its KeeperPAM offering also provides privileged access controls, session recording and audit trails intended to help institutions meet Family Educational Rights and Privacy Act (FERPA) and Children's Internet Protection Act (CIPA) requirements.
