Danish university DTU breach exposes data of up to 200,000 people

A Massive Data Breach Hits Denmark’s Top University, Exposing 200,000 Users’ Personal Information

The Technical University of Denmark (DTU) has fallen victim to a devastating cyberattack, which has compromised the sensitive data of up to 200,000 individuals. The breach, which occurred when hackers gained access to DTU’s identity and access management system, has left the university scrambling to notify those affected and mitigate the potential damage.

The attack appears to have been carried out by an individual or group that used compromised credentials to log into DTUBasen, a system responsible for managing user identities and access across the university. The hackers then downloaded a large amount of data, which includes sensitive information such as Danish civil registration numbers (CPR), full names, home addresses, and profile pictures.

But it’s not just current students and staff who are at risk – DTU has also confirmed that around 160,000 former users may have been affected. The dataset contains a wealth of personal details, including employment-related information such as work email addresses, job titles, office locations, and other sensitive data.

One of the most concerning aspects of this breach is the exposure of next-of-kin data, which includes names, relationships, and telephone numbers. This type of information can be particularly vulnerable to exploitation by cybercriminals, who may use it to launch targeted phishing attacks or commit identity fraud.

DTU has acknowledged that the attack was serious and has expressed regret for the uncertainty it is causing among those affected. The university has taken steps to establish the extent of the breach, limit its consequences, and ensure that those impacted are notified and provided with guidance on how to protect themselves.

One potential concern is that not all potentially affected individuals will be directly notified by DTU. While current and former employees will receive notification through e-Boks, a system used for sharing documents and notices with students and staff, students whose CPR numbers are held by DTU may not be contacted directly.

In an effort to reach those who cannot be contacted directly, DTU has released a public disclosure urging individuals to share the information with former employees, students, guests, and external partners. The university is also advising anyone who has been connected to DTU since 2003 to be cautious of suspicious emails, text messages, and phone calls.

In light of this breach, it’s essential for all users to remain vigilant about their online security. If you have a connection to DTU or any other organization that may have been affected by the breach, take these steps:

* Be cautious of unexpected communications that appear to be tailored to your personal details.

* Avoid sharing sensitive information such as passwords in response to unsolicited requests.

* Keep an eye on your credit reports and consider placing a credit alert on your CPR number.

* Consider changing the passwords for any other services that use the same credentials as your DTU account.

By taking these precautions, you can help mitigate the potential damage from this breach and stay one step ahead of cybercriminals.


Source: Bleeping Computer — 2026-10-03