Academic information systems manage sensitive data whose integrity directly affects academic administration and student outcomes. Legacy intranet-based systems may remain vulnerable to both technical attacks and human-factor threats, particularly when outdated software, unencrypted communication, weak access controls, and privileged user access coexist within the same operational environment. Objective: This study aims to analyze the security vulnerabilities of the Informatics Engineering Laboratory Information System (SILABTI) and identify potential pathways for unauthorized modification of practicum grades and graduation statuses using a hierarchical Attack Tree approach. Methodology: This study employed an analytical systems-engineering design based on Attack Tree threat modeling. The assessment covered the SILABTI web application, local network environment, MySQL database architecture, and administrative workflows. System boundaries and technical conditions were identified through infrastructure assessment and network reconnaissance, followed by hierarchical decomposition of adversarial objectives into root goals, intermediate sub-goals, and technical execution leaf nodes using AND/OR relationships. The resulting attack pathways were qualitatively evaluated according to technical prerequisites, execution complexity, system exposure, and detection probability. Findings: The analysis identified four primary intrusion vectors: credential acquisition, application exploitation, database exploitation, and insider exploitation. Four pathways were considered particularly high-risk: local network sniffing, workstation keylogging, automated brute-force attacks, and insider bribery or coercion. These findings indicate that SILABTI's security risks arise from the interaction of legacy software, network communication weaknesses, endpoint privileges, authentication controls, and human factors. Implications: The findings support an eight-point defense-in-depth framework incorporating TLS/HTTPS, tamper-resistant audit logging, role-based access control, network access restrictions, stronger authentication controls, workstation privilege restriction, anti-spoofing measures, and institutional security governance. This framework can guide university IT administrators in strengthening legacy academic information systems. Originality: This study contributes a hierarchical threat-decomposition model specifically designed for a legacy intranet-based academic laboratory information system, integrating technical and human-layer attack pathways within a single security assessment framework.