On the surface, the water looks calm.
That's what makes Shark Week fascinating every year. The danger is never visible on the surface. It's what's already moving underneath.
Cybercriminals operate the same way. The threats institutions face right now are designed to blend in with normal campus operations until the moment something breaks, money moves or systems go down. And with AI in their hands, those threats look more convincing than ever.
During the summer, when campus empties out, staff take time off and oversight gets thinner, cybercriminals know institutions are often paying less attention.
Here are three ways they're circling right now.
1. Fake invoices and vendor impersonation
Attackers don't need to hack anything. In many cases, they need to send just one believable email.
This is called business email compromise (BEC), and it works by impersonating a vendor, contractor or campus leader your team already trusts — a facilities supplier, a construction partner, even a dean. AI has made these messages even harder to spot: the grammar is flawless, the tone matches, and attackers can now mimic a familiar voice on a phone call.
The email arrives looking completely normal, someone in accounts payable or the bursar's office pays the "vendor," and by the time anyone realizes the request wasn't legitimate, the money is gone.
These attacks spike over the summer for a simple reason. When the people who normally approve payments are out, requests get rerouted to others who don't always know what normal looks like. Temporary stand-ins are less likely to question urgency, and attackers know it.
The fix is simple to implement: build a verification process for any financial or payroll request received by email. A quick confirmation call to a known number — not the number in the email — is enough to stop most of these before they go anywhere.
2. Phishing attacks that target distracted people
Phishing works because it's engineered around how people behave when they're busy.
Cybercriminals design these moments deliberately. A distracted staff member sees a password reset notice and clicks the link. A faculty member gets a text that looks like it came from IT. An email lands during onboarding asking a new hire to update direct-deposit details. A student gets a fake financial-aid message. Nobody stops to verify because stopping feels like losing time.
The most effective protection isn't a software solution; it's culture. A campus community that understands how AI-powered scams work is far harder to fool.
Faculty, staff and students need to feel comfortable slowing down when something seems off:
- An unexpected login or MFA request
- A payment or direct-deposit change that came out of nowhere
- A link in an email they weren't expecting
Speed is a weapon attackers use against you. Slowing down is how you take it away from them.
3. Third-party risks that travel fast
When a vendor with access to your systems is compromised, the threat doesn't stay contained to them. It travels directly into your environment through whatever connection they have to your institution.
This is supply chain exposure, and most campuses have far more of it than they realize. EdTech platforms connected to the SIS and LMS, service providers holding credentials, research collaborators sharing data and contractors whose access was never removed after a project ended all create paths most institutions have never mapped out.
Outsourcing a service doesn't outsource accountability — and under the GLBA Safeguards Rule, overseeing your vendors is now your responsibility.
Knowing where you stand with supply chain exposure means being able to answer three questions:
- Which vendors can access your data or systems?
- What are they connecting to?
- Who is responsible internally for managing those relationships?
If those answers aren't clear, your exposure is opening your institution up to risk.
By the time you see it, it's already moving
Sharks don't announce themselves, and neither do the cybercriminals targeting your campus right now.
The institutions that get hit aren't always the ones that ignore obvious warning signs. They're the ones that assume everything is fine because nothing looks wrong.
Summer is when schedules get loose, attention drifts and the water looks the calmest. It's also when attackers are most active — right as you're preparing for a full campus in the fall.
We help institutions get a clear picture of where they're exposed across vendors, faculty and staff activity, and day-to-day operations before something goes wrong. And because so many of today's attacks are built to fool busy people, we created Project NoéMI™ — credentialed with George Mason University — to help your campus build the AI fluency to recognize them, starting with a free first step.
If you don't know where your institution stands, sign up for the free AI Acceleration Platform: https://forms.newpush.com/join-noemi-trainer. Prefer to start with a conversation? Book a 15-minute discovery call.