Danish university DTU breach exposes data of up to 200,000 people

A massive data breach has struck the Technical University of Denmark (DTU), potentially exposing sensitive information for up to 200,000 individuals. Hackers exploited a vulnerability in DTU’s identity and access management system, known as DTUBasen, allowing them to download vast amounts of user data that spans nearly two decades.

The compromised credentials enabled attackers to gain access to the personal details of current students, staff, and former users. According to DTU, this sensitive information includes Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, office locations, and other employment-related details. Even more alarmingly, the dataset contained next of kin data, including names, relationships, and telephone numbers, which could be used for identity fraud or to make phishing attacks more convincing.

DTU’s Director Bjarke Bak Christensen acknowledged the severity of the breach and expressed regret for the uncertainty it has caused among those whose information may have been affected. “Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take,” he stated.

The university warns that cybercriminals could use the exposed CPR numbers and personal data for identity theft and phishing attacks. To mitigate this risk, DTU is urging potentially impacted individuals to be cautious when receiving unexpected communications or authentication requests. It’s essential to treat any emails, text messages, or phone calls from unknown individuals with suspicion and never disclose passwords or sensitive information in reply.

DTU will notify current and former employees directly through the official mailbox system, e-Boks, but not all students whose CPR numbers are held by the university. The public disclosure is part of DTU’s effort to reach potentially affected individuals it cannot contact directly, and the university is urging people to share this information with former employees, students, guests, and external partners.

If you believe your personal data may have been exposed in the breach, take immediate action. Change passwords for any other services that use the same credentials as your DTU account, place a credit alert on the affected CPR number, and be vigilant when receiving unsolicited communications or authentication requests. Remember, your vigilance is key to preventing identity theft and protecting yourself from potential cyber threats.

It’s worth noting that this breach serves as a reminder of the importance of robust identity and access management systems in organizations. Regular security audits, employee education on cybersecurity best practices, and proactive measures to prevent vulnerabilities can significantly reduce the risk of such breaches occurring.


Source: Bleeping Computer — 2026-10-03