The Technical University of Denmark (DTU) has disclosed a data breach that may have exposed personal information belonging to as many as 200,000 individuals. The incident involved unauthorized access to DTUBasen, the university's identity and access management (IAM) system, by an attacker using compromised credentials.
The university confirmed that a significant volume of data, spanning over two decades, was downloaded from DTUBasen. While DTU cannot definitively determine the exact information accessed or the precise number of affected individuals, the system holds data for approximately 40,000 active users and 160,000 former users.
For current users, potentially exposed data includes Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, and office locations. Additionally, if provided by active users, the names, relationships, and telephone numbers of their next of kin were also stored in the system and may have been compromised.
DTU noted that for former users, certain sensitive details such as home addresses, profile pictures, and next of kin information are automatically deleted from DTUBasen after six months. The university director, Bjarke Bak Christensen, expressed regret over the uncertainty caused by the attack and emphasized that the immediate priorities were to assess the breach's scope, mitigate its impact, and notify affected parties.
The university warns that the exposed CPR numbers and other personal data could be exploited for identity fraud and to craft more convincing phishing attacks. Individuals who have been employees, students, guests, or external partners of DTU since 2003 are advised to exercise caution regarding unexpected communications.
Notification will be primarily through e-Boks, DTU's official digital mailbox system for students and staff. All current and former employees will be notified directly. However, not all current and former students whose CPR numbers are held by DTU will receive direct notification. DTU clarified that it only holds CPR numbers for a limited number of guests and external partners, and not for next of kin whose contact details were registered.
As part of its efforts to reach all potentially affected individuals, DTU has issued a public disclosure and is urging people to share this information with former employees, students, guests, and external partners. Individuals are advised against disclosing passwords or sensitive information in response to unexpected communications and to be suspicious of sudden authentication requests. It is also recommended to change passwords for any other services that share credentials with DTU accounts and to place a credit alert on their CPR number.






