Jisc
News

Threat intelligence reveals increase in compromised credentials on the dark web

Over 144,000 username and password combinations for UK education and research identities were found in the twelve months up to June 2026, with monthly figures growing over that period.

We run the high-speed Janet Network for universities, colleges and research institutes in the UK. Built-in cyber protection and threat detection for our customers includes monitoring the dark web for compromised credentials uploaded by hackers around the world.

Monthly figures released for 2025/26 show between 3,500 and 26,300 comprised credentials discovered each month, with an upward trend over the year.

Bar chart titled 'Compromised credentials detected on the dark web by Jisc' showing the number of credentials detected each month from June 2025 to June 2026. The lowest figure is 3,500 in January 2026 and the highest figure is over 26,000 in May 2026. The trend line shows a three-fold increase over the year.

Our searches include all .ac.uk academic domains as well as .org and other domains for Jisc’s research, NGO, and public-sector customers. The credentials found include dumps of stolen identities obtained by infostealers, ransomware attacks, hacking groups and other criminal access brokers.

As owner of the Janet network, our position as both ISP and cyber-security provider allow us to directly monitor the academic network for security threats, while also focussing its web and dark web monitoring activity on the academic and research sectors. Connection to the Janet network includes Protective Domain Name System (DNS) and Distributed Denial of Service (DDoS) mitigation alongside the sector-specific threat intelligence monitoring.

Specialisation and network-level monitoring result in faster alerts to affected organisations with one college receiving notice of compromised credentials five days before the equivalent alert from the college’s insurance company. Threat intelligence, such as these dark web monitoring results, encourage education institutions to constantly strengthen their cyber security posture while we emphasise to sector leaders the value of their research and intellectual property to threat actors.

David Batho, head of cyber security, said:

“We expect network traffic over the Janet network to grow rapidly as customers choose the built-in security of Janet and its ability to handle the data transfers of high-performance computing. We also expect threat actors, with access to ‘hacking-as-a-service’ and AI tools, to increase their attacks on UK education and research and for our threat intelligence services to be in high demand.

“Data sources like the dark web monitoring, and our Janet Network resolver service (JNRS) which blocked over 61 million queries to malicious sites in the last year, illustrate the scale of cyber-security issues faced by our members . While the Janet network and Jisc’s built-in security services are a vital basic protection, we urge all UK education, research, public sector and charity organisations to do more to protect themselves, such as signing up for our 24/7 Security Operations Centre (SOC).”

Continue reading

Sign up to Headlines

Stay at the forefront of technology in education and research with our tailored fortnightly newsletter.