At a Glance
- Keeper Security warns education IT teams face a growing "hidden" attack surface from unmanaged machine identities during back-to-school onboarding
- Only 14% of schools mandate security awareness training, while 41% report being targeted by AI-generated phishing or misinformation campaigns
- Non-human identities—service accounts, API keys, IoT certificates, AI agents—now vastly outnumber human users on campus networks, yet remain largely unaudited
As millions of students return to campuses this autumn, cybersecurity firm Keeper Security is warning that the real threat to schools and universities may not be the flood of new human users, but an invisible population of machine identities that already outnumbers them. In new guidance issued ahead of the academic year, the company argues that service accounts, API keys, IoT certificates and AI agents now represent a larger and less-governed attack surface than the students, faculty and staff IT departments typically focus on protecting.
Why Back-to-School Season Is a Security Blind Spot
The education sector has long ranked among the most targeted industries for ransomware and data theft, a status driven by a familiar mix: high-value student and financial records sitting alongside IT departments that are frequently under-resourced. Back-to-school season compounds that exposure because bulk account creation, mass device enrollment and rapid third-party application onboarding all occur within a compressed window.
Keeper's research found that just 14% of schools mandate security awareness training, a gap reflected in user behaviour: nearly one in five students and parents admit to reusing passwords across personal and school accounts. That combination of weak training and password reuse gives attackers a foothold at precisely the moment institutions are least equipped to monitor it.
Artificial intelligence has sharpened the danger further. Phishing emails can now convincingly mimic messages from financial aid offices or IT helpdesks, while deepfake audio and video add a further layer of deception. Forty-one percent of institutions surveyed said they had already been targeted by AI-generated phishing attempts or misinformation campaigns, according to the firm's data.
"The conversation about education cybersecurity has historically focused on human accounts: students, teachers and administrators. But the real blind spot is the vast ecosystem of machine identities that power modern EdTech. Back-to-school is the right moment for education IT teams to take stock of every identity on their network, human and non-human alike."

