Technical University of Denmark Breach Exposes Data for 200,000
The Technical University of Denmark reported a major security breach affecting up to 200,000 current and former users after attackers gained access to its identity and access management system.

Identity and Access Management System Compromised
The Technical University of Denmark (DTU) announced that information belonging to as many as 200,000 users may have been exposed following a security incident. According to a detailed report by BleepingComputer, hackers managed to access the university's identity and access management system, subsequently downloading a large volume of data spanning more than two decades.
In a disclosure published on Friday, the university explained that the attacker utilized compromised credentials to log into DTUBasen, which serves as its primary identity and access management infrastructure. This unauthorized access granted the perpetrators entry into user data accumulated over more than twenty years.
Scope of the Affected User Data
DTU confirmed that it cannot precisely determine the exact scope of what was downloaded or the exact number of individuals affected by the incident. However, university records indicate that DTUBasen stores data for approximately 40,000 active users alongside roughly 160,000 former users.
For current users, the potentially exposed information includes full names, home addresses, profile pictures, work email addresses, job titles, office locations, and other employment-related records. Additionally, the impacted dataset contained Danish civil registration numbers, commonly known as CPR numbers, as well as the names, relationships, and telephone numbers of users' next of kin where provided.
The university noted that for former users, certain data types such as home addresses, profile pictures, and next of kin information are subject to automatic deletion after a period of six months.
University Response and Official Warnings
University Director Bjarke Bak Christensen addressed the incident, calling it a serious attack on the institution. He expressed deep regret over the uncertainty and concern caused for individuals whose personal information may have been compromised during the breach.
“Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take,” Christensen stated. Further details regarding the official response can be found directly through the organization says portal.
DTU warned that the exposed CPR numbers and other personal records could be exploited by cybercriminals to execute identity fraud or make subsequent phishing attacks significantly more convincing to victims.
Notification Process for Impacted Individuals
Potentially impacted individuals are scheduled to receive notifications via e-Boks, which is the official mailbox system utilized by DTU for sharing documents and formal notices with its students and staff members.
However, the university clarified that it will notify all current and former employees, but it will not directly notify every single current and former student whose CPR numbers are maintained within the system. Because of this limitation, the public disclosure forms an essential part of DTU's outreach strategy to reach those who cannot be contacted directly.
The organization emphasizes that anyone who has served as an employee, student, guest, or external partner at DTU at any point since 2003 could potentially be affected by the data security breach.
Recommended Security Precautions
In light of the breach, affected individuals and members of the university community are strongly advised to exercise heightened caution regarding unsolicited emails, text messages, and phone calls. Attackers may attempt to leverage inside knowledge or personal details to establish false trust.
DTU recommends that users avoid disclosing passwords or sensitive information in response to unexpected communications. Any sudden authentication prompts or login requests should likewise be treated with a high degree of suspicion.
Finally, security guidance suggests changing passwords for any external services that share credentials with a DTU account, alongside placing a credit alert on the affected CPR number to mitigate risks associated with potential identity theft.
Sources
- BleepingComputerDanish university DTU breach exposes data of up to 200,000 people
Continue chronologically



