Keeper Security warns education IT teams over AI phishing and machine identity risks

Keeper Security warns education IT teams over AI phishing and machine identity risks

Keeper Security has urged schools, colleges and universities to strengthen identity security ahead of the new academic year as Artificial Intelligence-powered phishing, deepfake impersonation and unmanaged non-human identities expand the education sector’s attack surface.

Education IT teams are being urged to review identity security ahead of the new academic year as Artificial Intelligence-powered attacks and growing numbers of non-human identities create additional cybersecurity risks.

Keeper Security said the annual influx of students, faculty and staff requires institutions to create large numbers of accounts, issue credentials, connect devices and introduce third-party applications over a relatively short period.

The company warned that this activity can create opportunities for attackers to exploit misconfigurations, compromised credentials and gaps in access controls.

Keeper research found only 14% of schools mandate security awareness training, while nearly one in five students and parents reuse passwords across personal and school accounts.

Artificial Intelligence is also changing the phishing threat. Attackers can generate communications designed to imitate messages from IT helpdesks, student funding departments or university leaders, while deepfake technology can add convincing voice and video impersonations.

According to Keeper, 52% of education leaders identify deepfake impersonation as a leading concern but only 26% are confident in their ability to recognise AI-enabled threats. The company also reported that 41% of institutions have been targeted by AI-generated phishing attempts or misinformation campaigns.

Keeper highlighted non-human identities as another growing area of risk within education environments. These can include service accounts connecting student information and learning management systems, API keys used by third-party applications, machine identities, digital certificates, cloud workloads and AI agents.

Service accounts and integration credentials can remain active after they are no longer required, while cloud identities can have broader permissions than necessary. AI agents used for applications including admissions chatbots, helpdesk automation and grading assistants can also have their own identities and access privileges.

Darren Guccione, CEO and Co-founder, Keeper Security, said: “The conversation about education cybersecurity has historically focused on human accounts: students, teachers and administrators. But the real blind spot is the vast ecosystem of machine identities that power modern EdTech. Back-to-school is the right moment for education IT teams to take stock of every identity on their network, human and non-human alike.”

Keeper recommends institutions enforce multi-factor authentication across student and employee accounts and audit privileged access before the academic year begins. IT teams should also remove credentials belonging to former employees, expired service accounts and applications that are no longer being used.

The company is additionally encouraging institutions to create inventories covering service accounts, API keys, machine certificates, cloud identities and AI agents and establish credential rotation policies for machine identities.

Keeper said phishing awareness programmes should also be updated to reflect the increasing sophistication of AI-generated communications, which may be more difficult for students and employees to distinguish from legitimate messages.

The company argues that combining stronger controls over human accounts with greater visibility and governance of non-human identities will become increasingly important as schools, colleges and universities introduce more cloud services, EdTech integrations and Artificial Intelligence tools.

Browse our latest issue

Intelligent Edu.tech

View Magazine Archive