corporate_fareBusiness News & Info
TechnologyNews Brief

Machine Identities Outnumber Students in Campus IT Risk

Daniel HartleyDaniel Hartley15 August 2026677 words
Machine Identities Outnumber Students in Campus IT Risk

Click Below To Share & Ask AI to Summarize This Article

Save time and get the key takeaways instantly. Choose your favourite AI assistant to read and analyse this page for you.

At a Glance

  • Keeper Security warns education IT teams face a growing "hidden" attack surface from unmanaged machine identities during back-to-school onboarding
  • Only 14% of schools mandate security awareness training, while 41% report being targeted by AI-generated phishing or misinformation campaigns
  • Non-human identities—service accounts, API keys, IoT certificates, AI agents—now vastly outnumber human users on campus networks, yet remain largely unaudited

As millions of students return to campuses this autumn, cybersecurity firm Keeper Security is warning that the real threat to schools and universities may not be the flood of new human users, but an invisible population of machine identities that already outnumbers them. In new guidance issued ahead of the academic year, the company argues that service accounts, API keys, IoT certificates and AI agents now represent a larger and less-governed attack surface than the students, faculty and staff IT departments typically focus on protecting.

Why Back-to-School Season Is a Security Blind Spot

The education sector has long ranked among the most targeted industries for ransomware and data theft, a status driven by a familiar mix: high-value student and financial records sitting alongside IT departments that are frequently under-resourced. Back-to-school season compounds that exposure because bulk account creation, mass device enrollment and rapid third-party application onboarding all occur within a compressed window.

Keeper's research found that just 14% of schools mandate security awareness training, a gap reflected in user behaviour: nearly one in five students and parents admit to reusing passwords across personal and school accounts. That combination of weak training and password reuse gives attackers a foothold at precisely the moment institutions are least equipped to monitor it.

Artificial intelligence has sharpened the danger further. Phishing emails can now convincingly mimic messages from financial aid offices or IT helpdesks, while deepfake audio and video add a further layer of deception. Forty-one percent of institutions surveyed said they had already been targeted by AI-generated phishing attempts or misinformation campaigns, according to the firm's data.

"The conversation about education cybersecurity has historically focused on human accounts: students, teachers and administrators. But the real blind spot is the vast ecosystem of machine identities that power modern EdTech. Back-to-school is the right moment for education IT teams to take stock of every identity on their network, human and non-human alike."

— Darren Guccione, CEO and Co-founder, Keeper Security
Machine Identities Outnumber Students in Campus IT Risk
Machine Identities Outnumber Students in Campus IT Risk

The Machine Identity Problem Nobody Is Counting

Beneath the human-facing systems that schools spend most of their security budgets protecting, Keeper identifies a far larger population of non-human identities that few institutions formally inventory. Service accounts synchronise data between student information systems and learning platforms, often running on credentials that are rarely rotated or audited. API keys link digital textbooks, library databases and payment gateways to central systems, and orphaned tokens from prior-year integrations frequently stay active long after they are needed.

Machine identities also authenticate an expanding roster of connected hardware: smart boards, lab equipment, 3D printers and security cameras, each relying on digital certificates that can expire or be misconfigured without anyone noticing. Cloud-managed identities running on platforms such as Azure, AWS and Google Cloud frequently carry broader permissions than their automated tasks actually require, while AI-powered admissions chatbots and grading assistants add yet another fast-growing category of unmanaged access.

This pattern is not unique to education; it mirrors a broader corporate trend in which automated systems and AI agents multiply faster than the governance frameworks meant to control them. The same dynamic that is prompting enterprises to rethink AI-driven risk assessment, as seen in defense and research sectors adopting AI's rise in specialized research, is now surfacing in classrooms and university IT departments that have far smaller budgets to respond.

Keeper's guidance frames the fundamentals as manageable for most institutions: enforcing multi-factor authentication, auditing privileged access and removing stale credentials before new users arrive. The harder challenge, the firm suggests, lies in building durable visibility into machine identities that most schools have never formally counted, a task that will likely define education cybersecurity spending well beyond this single admissions cycle.

Stay Ahead of the News

Get the latest business news and company spotlights delivered to your inbox. No spam, unsubscribe any time.

We respect your privacy. Unsubscribe at any time.