Keeper Security is warning K-12 districts and universities that AI-powered phishing, deepfake impersonation, and a surge of unmanaged 'non-human identities' — service accounts, API tokens, machine certificates — pose growing risks during fall enrollment rushes. The company's own research found only 14% of schools mandate security awareness training, nearly one in five students and parents reuse passwords across school and personal accounts, and 41% of institutions report being targeted by AI-generated phishing or misinformation. It also found 52% of education leaders see deepfake impersonation as a top concern, but only 26% feel confident spotting AI-enabled threats.
Keeper recommends schools enforce multifactor authentication, audit privileged access, remove stale credentials, and build visibility into machine identities before the semester starts. The company pitches its own KeeperPAM platform as a tool to discover and govern these accounts and help institutions meet FERPA and CIPA compliance requirements.
The full dispatch is available from the source below.