What is cyber security - and why is it important in scholarly communications?
New to cybersecurity? Start here.
Summary
Cybercrime affects the whole scholarly communications community: libraries, universities, and publishers. Cybersecurity is our response to it. By working together, we can build resilience across the sector and become part of the solution.
Cybersecurity is the practice of protecting ourselves from cyberattacks. These typically come from criminals or state-sponsored actors.
It matters in scholarly communications because the higher education sector is particularly vulnerable.
Common threats include phishing, malware, ransomware, and data theft.
Digital piracy is a particular threat. Journal articles may be stolen and put on pirate sites. This threatens the integrity of research.
Artificial intelligence (AI) carries new threats. These include large language models (LLMs) being trained on pirated research.
By understanding the risks, and working together, we can build resilience across the scholarly communications community.
If you are new to cybersecurity, it can seem a tricky, technical topic to grasp. This post is our simple explainer of what cybersecurity is – and why it is important in scholarly communications. Cybercrime affects the whole of the research community: librarians, researchers, universities, and publishers. Understanding the problem is the first step to addressing it and building resilience.
What is cybersecurity?
Cybersecurity is about protecting ourselves from hackers. It is the practice of protecting computers, servers, mobile devices, networks, and data from digital attacks, damage, theft, or unauthorized access.
Cybercriminals may try to trick people into revealing their login details or clicking on malicious links (‘phishing’). Those links may download malicious software (‘malware’), including a particular type that locks people out of their files or computers until a ransom is paid (‘ransomware’). Cyberattacks can also be used to steal data. Data theft and digital piracy are particular risks in scholarly communications. Data theft may include personal details and login credentials. These may then be used to steal digital content such as journal articles, research, or other intellectual property (IP). Journal articles may be stolen, in bulk, and put on illegal pirate websites.
The main aim of cybersecurity is therefore to stop unauthorized people or groups from accessing or stealing digital information. Two main groups are typically involved: criminals seeking data for financial gain; and state-sponsored actors seeking personal data or IP for strategic advantage.
Artificial intelligence (AI) brings with it potential new threats to cybersecurity. Pirated books and journal articles – which may be inaccurate – have been used to train AI models. AI chatbots such as ChatGPT or Claude may be used by criminals to create malicious code or write phishing emails. Yet there are also opportunities to use AI to help spot and react to breaches.
We all rely on digital services and devices these days. Cybersecurity helps individuals and organizations reduce the risk and impact of cyberattacks. Those organizations include libraries, universities, research institutions, and publishers.
Why does cybersecurity matter in scholarly communications?
Cybersecurity matters in scholarly communications because the higher education sector is particularly vulnerable to cyberattacks. It is easy to think that nonprofit and public sector organizations have less exposure to risk from cybercriminals. Historically, universities may have underestimated the threat as a result. Our own research suggests this is the case. Yet cybersecurity is not just something for big businesses to worry about.
In 2019 the UK’s National Cyber Security Centre (NCSC) published a report into The cyber threat to Universities. This revealed that over 300 fake websites and login pages were discovered in 2018, targeting 76 universities across 14 countries. And the problem is growing. According to a UK Government report, almost every UK university (98%) identified breaches or attacks in 2025. A report from Quorum Cyber stated that the number of data breaches in the higher education sector globally jumped by 73% in the same year.
The sector is vulnerable due to the large amount of personal and research data that universities and library systems store, and the valuable IP they hold. Journal articles and research material may be stolen and put on illegal pirate sites. This not only leaves universities, libraries and other institutions open to costly cyberattacks, data breaches, and reputational damage, it threatens the integrity of research itself. The theft of copyrighted materials also damages the legitimate business of publishers, who strive to keep the academic record accurate.
Beyond these risks, state-sponsored breaches can also damage the value of research, reduce public and private investment in affected universities, and erode national knowledge benefits. This is particularly notable in STEM subjects.
Cybersecurity in scholarly communications exists to protect IP, secure sensitive user data from threats like phishing and ransomware and maintain the integrity of the research record.
Who is affected by cybercrime in scholarly communications?
Cybercrime affects the whole research community because of the interconnectedness of scholarly communications.
Libraries
Library systems handle huge volumes of content and sensitive data. This may include research, and the personal data of people who use the library, including student records. Because academic libraries manage vast, valuable research databases and connect to broader university networks, they are prime targets. Libraries and universities may be the victims of phishing attacks, malware, and data theft.
Universities
As part of our 2025 Cybersecurity and Academic Libraries research we conducted interviews with 20 university Chief Information Security Officers (CISOs). They shared a wide range of breach types they saw. These included phishing, financial fraud, and mass downloads of journal articles resulting from the use of stolen or leaked login details.
Publishers
Publishers are a frequent target for content piracy and IP theft. This makes it harder to keep the scholarly record accurate and publish new research findings. It also comes at a time when publishers are working hard to make research findings more open and accessible by legitimate means, through open access to publications and data. Because they sit at the centre of the scholarly record, publishers are often the first to notice when something is wrong. That might include irregular download activity or unusual account behaviour, which is spotted via their platform analytics.
Wider society
Beyond these threats to organizations, society as a whole suffers if research is stolen, because it threatens the integrity of research itself. Research that is essential to advance knowledge and develop policy.
At SNSI we work with librarians, IT and cybersecurity teams in universities, publishers, and other stakeholders across the scholarly communications community. Read more about who we work with.
What are the main cybersecurity threats?
Cybersecurity threats typically include malware, ransomware, phishing, and data theft. These can be costly to remedy, and may lead to reputational damage. Some of the main threats are:
Malware. Short for ‘malicious software’, malware is any code or program intentionally designed to damage, disrupt, steal data, or gain unauthorized access to computers, servers, or networks.
Ransomware. A type of malware that prevents people from accessing their computer, network, or the data held on them. In these attacks, people are locked out of their computers or files unless a ransom is paid to hackers. The data is usually encrypted – but it may also be deleted or stolen.
Phishing. Phishing emails are used by cybercriminals to trick people into giving away their login details or clicking on a link that downloads malware. Phishing can also take place via text messages or phone calls. This is a type of cyberattack that is also called social engineering.
Data theft. Identity and credential theft are common aims of cyberattacks. Login details that are stolen may then be used for further data theft. That may include research papers, journal articles, and data held on university, library, or publisher systems.
Read more about cybersecurity threats on our FAQs page.
Digital piracy – a threat to research integrity
Piracy is a particular kind of threat that affects scholarly communications. This is not just a threat to publishers. It threatens the integrity of the scholarly record itself.
Pirate sites in scholarly communications are online platforms that provide unauthorized, free access to stolen journal articles and books. Known pirate sites include Sci-Hub, Library Genesis (LibGen), Z-Library, and Anna’s Archive.
Digital piracy damages research integrity and the research process itself. Unlike publishers, pirate sites have no incentive to ensure the accuracy of research reports, uphold ethical standards, or correct and retract content where issues arise. Publishers take their duty of care for the scholarly record very seriously. Pirate sites undermine the research process by taking what others have invested in.
Pirate sites are also a threat to university networks. A 2022 SNSI guest post for the Scholarly Kitchen highlights that the UK police have previously warned students and universities against using them. In 2021 the City of London Police’s Intellectual Property Crime Unit (PIPCU) publicly warned against the use of sites such as Sci-Hub, primarily because of how they operate: by using, among other means, phishing emails to trick university staff and students into divulging their login credentials. These are then used to compromise the university’s network. PIPCU reports that many universities around the world have suffered intrusions as a result of access credentials being stolen when visiting the Sci-Hub website.
Read more about pirate sites on our FAQs page.
AI and cybersecurity in scholarly communications
AI poses new risks for cybersecurity in scholarly communications. Large language models (LLMs) – the technology behind AI tools such as ChatGPT and Claude – are trained on vast amounts of text data. There is growing evidence that some AI developers have used pirate sites, including Sci-Hub and LibGen, as training data sources, without the consent of authors or publishers.
This raises serious concerns. Not only does it represent large-scale copyright infringement, but it may also mean that AI systems are being built on content that has been retracted or not properly verified and corrected as needed. This means that there is no guarantee of accuracy or integrity in the foundation of these tools.
Aside from AI models being trained on pirated material, these tools may themselves be used by cybercriminals to write malicious code, automate attacks, or write targeted phishing emails. In July 2026 there were even reports of both ChatGPT and Claude ‘going rogue’ and hacking websites.
The flipside is that AI may also be used to detect breaches and help automate responses. Like the internet as a whole, AI is a tool that can be used for good or ill and has both risks and benefits.
This is a rapidly moving field, and one that SNSI monitors closely as part of its broader work on threats to the scholarly record. You can read more about AI and cybersecurity on the UK’s National Cyber Security Centre (NCSC) website.
A shared responsibility
We need to work together to address cybercrime. For example, publishers are often the first to detect breaches, through irregular download activity or platform analytics. They can alert institutions before internal systems catch it. This kind of cross-sector visibility is central to what SNSI exists to support.
By working together, we can pursue an important, shared goal: to safeguard successful, secure scholarly communications. To do this, we need to ensure legitimate institutional and individual access to high-quality, peer-reviewed publications. We need to protect data and safeguard the entitlements of institutions to the materials they have licensed.
Cybersecurity is a rapidly changing field. It is important to keep up with the latest developments and stay informed of emerging threats. SNSI brings together the people and organizations best placed to respond to the cybersecurity threats faced by the scholarly communications community. We share intelligence and research, develop resources, host an annual SNSI Security Summit, and advocate for a more secure and resilient research ecosystem.
By staying informed, we can become more resilient. Together, we can become part of the solution.