Thousands of stolen student data found on the dark web

Rising cyber threats to higher education cyberattacks have been uncovered

The data of thousands of university students has been discovered on the dark web.

More than 144,000 stolen username and password combinations of people in higher education and research in the UK were found on the dark web in the year leading up to June, according to digital services organisation Jisc.

The findings were uncovered during Jisc’s regular monitoring of “compromised credentials” under their Janet Network service, built to support higher educational institutions.

It’s thought that the details ended up online after “dumps” of stolen identities by hacking groups and those responsible for ransomware attacks.

Figures from 2025-2026 reveal a rising trend in the number of vulnerable passwords and accounts, with an increase from 10,000 to 15,000 uncovered compromised identities in the past year.

These figures follow the recent University of Nottingham cyber attack, which lead to hundreds of thousands of student and alumni data being seized by hackers after its Campus Solutions system was accessed in May 2026. The hackers gained information to students personal, financial and university-related data.

Since 2020, eight Russell Group universities have received direct attacks, including the University of Oxford and the University of Cambridge.

Via Unsplash

David Batho, head of cybersecurity at Jisc, said the organisation expects “threat actors, with access to ‘hacking-as-a-service’ and AI tools, to increase their attacks on UK education and research.”

The Janet Network blocked more than 61 million queries to malicious sites in the last year, he added, illustrating “the sale of cybersecurity issues faced by our members.”

Nicole Stewart, Jisc’s head of security intelligence and capability, told Times Higher Education (THE): “There’s been this steady increase over the years of ‘infostealers’, a kind of malware that secretly scans a computer for personally identifiable information. When a victim has an infostealer on their laptop, that’s obviously just collecting all their credentials. The difficulty with the education sector is the way that it’s set up, with the fact that a lot of students bring their own devices that [universities] don’t have management over, so any malware that’s on these devices which could be stealing credentials [institutions] don’t have that visibility and control over.

Nicole said she believed the sector to be “very aware of the risks” but urged institutions to stay up to date with Jisc’s alerts for individual organisations regarding potentially compromised accounts: “Ransomware is one of the major threats for the sector. It’s not something were being declining (…) it’s a really important threat.”

For more of the latest news, guides, gossip and memes, follow The Nottingham Tab on InstagramTikTok and Facebook.

Featured image via Unsplash