DKDKCISSPSearch
Data Breaches

Danish university DTU breach exposes data of up to 200,000 people

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.

DKCISSP News DeskBleepingComputer3 Oct 2026, 8:05 pm
Danish university DTU breach exposes data of up to 200,000 people
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.

​The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management (IAM) system, allowing access to more than two decades of user data.

In a disclosure on Friday, DTU confirmed that it cannot “determine precisely what information was downloaded or how many people have been affected.” However, the Danish university notes that DTUBasen stores information for nearly 40,000 active users and around 160,000 former users.

DTU warns that cybercriminals could use the exposed CPR numbers and other personal data for identity fraud and to make phishing attacks more convincing.

The organization says that anyone who has been an employee, student, guest, or external partner of DTU since 2003 may be affected by the data breach.

Potentially exposed information for current users includes Danish civil registration numbers (CPR), full names, home addresses, and profile pictures, as well as work email addresses, job titles, office locations, and other employment-related details.

The public dicslosure is part of DTU’s effort to reach potentially affected individuals it cannot contact directly, and the university is urging people to share it with former employees, students, guests, and external partners.

Potentially impacted individuals will be notified through e-Boks, the official mailbox system that DTU uses for sharing documents and notices with students and staff.

DTU notes that in the case of former users, details about home addresses, profile pictures, and information about next of kin are automatically deleted after six months.

Additionally, it is recommended to change the passwords for any other services that use the same credentials as the DTU account and place a credit alert on the affected CPR number.

What happened

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.

​The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management (IAM) system, allowing access to more than two decades of user data.

What changed

In a disclosure on Friday, DTU confirmed that it cannot “determine precisely what information was downloaded or how many people have been affected.” However, the Danish university notes that DTUBasen stores information for nearly 40,000 active users and around 160,000 former users.

DTU warns that cybercriminals could use the exposed CPR numbers and other personal data for identity fraud and to make phishing attacks more convincing.

Who is affected

The organization says that anyone who has been an employee, student, guest, or external partner of DTU since 2003 may be affected by the data breach.

Potentially exposed information for current users includes Danish civil registration numbers (CPR), full names, home addresses, and profile pictures, as well as work email addresses, job titles, office locations, and other employment-related details.

Why it matters

The public dicslosure is part of DTU’s effort to reach potentially affected individuals it cannot contact directly, and the university is urging people to share it with former employees, students, guests, and external partners.

Potentially impacted individuals will be notified through e-Boks, the official mailbox system that DTU uses for sharing documents and notices with students and staff.

Technical details

DTU notes that in the case of former users, details about home addresses, profile pictures, and information about next of kin are automatically deleted after six months.

Additionally, it is recommended to change the passwords for any other services that use the same credentials as the DTU account and place a credit alert on the affected CPR number.

Passwords and sensitive information should not be disclosed in replies to unexpected communications, and sudden authentication requests or logins should be treated as suspicious.

Response

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Attribution

BleepingComputer: The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.