AGP Picks
View all

Keeper warns education IT teams about AI phishing and machine identities

4 hours ago
By AI, Created 06:00 UTC, Aug 13, 2026, AGP -

Keeper Security is urging schools and universities to harden systems before the new academic year as AI-powered phishing, deepfake impersonation and unmanaged non-human identities widen the attack surface. The guidance comes as education leaders face rising credential theft risks and limited security awareness training across campuses.

Why it matters: - Schools and universities are entering the highest-risk period of the year as they onboard new students, staff and devices. - AI-generated phishing, deepfake impersonation and unmanaged machine identities are making credential theft and data breaches harder to stop. - Education institutions hold student records, financial data and research assets, while many IT teams remain underfunded and stretched thin.

What happened: - Keeper Security released cybersecurity guidance for primary, secondary and higher education IT teams ahead of the new academic year. - The guidance focuses on the back-to-school rush, when bulk account creation, device enrollment and new third-party app onboarding create a temporary security gap. - Keeper said the education sector remains a major target for ransomware, credential theft and data breaches.

The details: - Keeper research found only 14% of schools mandate security awareness training. - Nearly one in five students and parents reuse the same passwords across personal and school accounts, according to Keeper research. - 52% of education leaders identify deepfake impersonation as a top concern, but only 26% feel confident spotting AI-enabled threats. - 41% of institutions say they have been targeted by AI-generated phishing attempts or misinformation campaigns. - Service accounts often sync student records between systems such as SIMS, Arbor or Banner and learning platforms such as Canvas, Blackboard or Google Classroom. - API keys and integration tokens connect learning apps, digital textbooks, library databases and payment gateways to central databases, and orphaned tokens from old integrations often stay active. - Machine identities and digital certificates support campus Wi-Fi, smart boards, lab equipment, 3D printers and security cameras. - Cloud-managed identities and workloads on Azure, AWS and Google Cloud handle backups, research pipelines and reporting, often with broader permissions than they need. - AI agents and bots used for admissions chatbots, helpdesk scripts and grading assistants carry their own access rights and are among the fastest-growing non-human identities in education. - Keeper said non-human identities outnumber human users by a wide margin in many institutions, yet few schools keep a full inventory of them. - Darren Guccione, CEO and co-founder of Keeper Security, said the real blind spot is the ecosystem of machine identities that power modern EdTech. - Guccione said back-to-school is the right time for IT teams to take stock of every identity on the network, human and non-human alike.

Between the lines: - The problem is shifting from classic password hygiene to identity sprawl across both people and machines. - Education IT teams now need visibility into a wider set of assets, including AI agents and third-party integrations that may never be reviewed after deployment. - The rise of accessible AI tools lowers the skill barrier for attackers, which means smaller schools are exposed to tactics once aimed mainly at large institutions.

What's next: - Keeper recommends enforcing MFA across faculty, staff and student accounts before onboarding starts. - Keeper also recommends deploying an enterprise password manager, auditing privileged access, building a non-human identity inventory and setting credential rotation policies for machine identities. - Institutions are advised to update phishing awareness training so staff and students can spot AI-generated messages that may look legitimate. - Keeper says its zero-trust, zero-knowledge platform can discover, govern and rotate credentials for human users and non-human identities. - KeeperPAM is positioned to support audit trails and privileged controls tied to UK GDPR, the Data Protection Act 2018 and Department for Education safeguarding and filtering requirements. - More information is available in the company's announcement.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Education Press Releases

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Education Press Releases

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.