Stolen account details of peopleĀ working in higher education are increasingly appearing on the dark web, raising the risk of cyberattacks for universities and research organisations.
More than 144,000 username and password combinations belonging to people involved in education and research in the UK were found to be compromised in the 12 months to June this year, digital services organisation Jisc has found.
The findings follow a spate of high-profile cyberattacks on major institutions, with a hijackedĀ student records platform at the University of Nottingham recently leading to the details of hundreds of thousands of students and alumni being seized by hackers.
The rising threat levelĀ was uncovered during Jiscās regular monitoring of ācompromised credentialsā, as part of its , built to support universities, colleges and research institutions with their digital connectivity.
Āé¶¹
Monthly figures for the 2025-26 period reveal an upward trend in the number of vulnerable passwords and accounts. Fewer than 10,000 compromised identities were uncovered in June last year but, a year on, there were 15,000 recorded.
Two months in particular clocked a significant number of cases: in April 2026, just over 20,000 credentials were discovered on the dark web, while in May this year that figure rose above 25,000.
Āé¶¹
Jiscās searches incorporate all āac.ukā academic domains, as well as ā.orgā addresses for its customers in research or the public sector and those representing non-governmental organisations.
It is thought that the details ended up online afterĀ ādumpsā of stolen identities by hacking groups andĀ those responsible for ransomware attacks.
David Batho, head of cybersecurity at Jisc, said the organisation expects āthreat actors, with access to āhacking-as-a-serviceā and AI tools, to increase their attacks on UK education and researchā.
The Janet Network blocked more than 61 million queries to malicious sites in the last year, he added, illustrating āthe scale of cybersecurity issues faced by our membersā.
Āé¶¹
Nicole Stewart, Jiscās head of security intelligence and capability, toldĀ Times Higher EducationĢż(THE) that āthereās been this steady increase over the years of āinfostealersā, a kind of malwareĀ thatĀ secretly scans a computer for personally identifiable informationā.
āWhen a victim has an infostealer on their laptop, thatās obviously just collecting all their credentials,ā she explained. āThe difficulty with the education sector is the way that itās set up, with the fact that a lot of students bring their own devices that [universities] donāt have management over, so any malware thatās on these devices which could be stealing credentials [institutions] donāt have that visibility and control over.ā
Stewart said she believed the sector to be āvery aware of the risksā but urged institutions to stay up to date with Jiscās alerts for individual organisations regarding potentially compromised accounts.
āRansomware is one of the major threats for the sector. Itās not something that weāre seeing declineā¦itās a really important threat.ā
Āé¶¹
Register to continue
Why register?
- Registration is free and only takes a moment
- Once registered, you can read 3 articles a month
- Sign up for our newsletter
Subscribe
Or subscribe for unlimited access to:
- Unlimited access to news, views, insights & reviews
- Digital editions
- Digital access to °Õ±į·”ās university and college rankings analysis
Already registered or a current subscriber?








