Tens of thousands of university account logins found on dark web

Rise in compromised credentials increasing risk of damaging cyberattacks, UK IT body warns

Published on
July 28, 2026
Last updated
July 28, 2026
Source: Getty/Yuliya Taba

Stolen account details of people working in higher education are increasingly appearing on the dark web, raising the risk of cyberattacks for universities and research organisations.

More than 144,000 username and password combinations belonging to people involved in education and research in the UK were found to be compromised in the 12 months to June this year, digital services organisation Jisc has found.

The findings follow a spate of high-profile cyberattacks on major institutions, with a hijacked student records platform at the University of Nottingham recently leading to the details of hundreds of thousands of students and alumni being seized by hackers.

The rising threat level was uncovered during Jisc’s regular monitoring of “compromised credentials”, as part of its Janet Network service, built to support universities, colleges and research institutions with their digital connectivity.

ADVERTISEMENT

Monthly figures for the 2025-26 period reveal an upward trend in the number of vulnerable passwords and accounts. Fewer than 10,000 compromised identities were uncovered in June last year but, a year on, there were 15,000 recorded.

Two months in particular clocked a significant number of cases: in April 2026, just over 20,000 credentials were discovered on the dark web, while in May this year that figure rose above 25,000.

ADVERTISEMENT

Jisc’s searches incorporate all “ac.uk” academic domains, as well as “.org” addresses for its customers in research or the public sector and those representing non-governmental organisations.

It is thought that the details ended up online after “dumps” of stolen identities by hacking groups and those responsible for ransomware attacks.

David Batho, head of cybersecurity at Jisc, said the organisation expects “threat actors, with access to ‘hacking-as-a-service’ and AI tools, to increase their attacks on UK education and research”.

The Janet Network blocked more than 61 million queries to malicious sites in the last year, he added, illustrating “the scale of cybersecurity issues faced by our members”.

ADVERTISEMENT

Nicole Stewart, Jisc’s head of security intelligence and capability, told Times Higher Education (THE) that “there’s been this steady increase over the years of ‘infostealers’, a kind of malware that secretly scans a computer for personally identifiable information”.

“When a victim has an infostealer on their laptop, that’s obviously just collecting all their credentials,” she explained. “The difficulty with the education sector is the way that it’s set up, with the fact that a lot of students bring their own devices that [universities] don’t have management over, so any malware that’s on these devices which could be stealing credentials [institutions] don’t have that visibility and control over.”

Stewart said she believed the sector to be “very aware of the risks” but urged institutions to stay up to date with Jisc’s alerts for individual organisations regarding potentially compromised accounts.

“Ransomware is one of the major threats for the sector. It’s not something that we’re seeing decline…it’s a really important threat.”

ADVERTISEMENT

georgia.luckhurst@timeshighereducation.com

Register to continue

Why register?

  • Registration is free and only takes a moment
  • Once registered, you can read 3 articles a month
  • Sign up for our newsletter
Please
or
to read this article.

Related articles

Sponsored

Featured jobs

See all jobs
ADVERTISEMENT