DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) has disclosed a data breach that may affect up to 200,000 current and former users. Hackers logged into the university's identity and access management system and downloaded a large volume of data.
According to DTU, the attacker used compromised credentials to access DTUBasen, the university's identity and access management (IAM) platform. That system holds user records going back more than 20 years.
In its Friday disclosure, the university said it cannot "determine precisely what information was downloaded or how many people have been affected."
DTUBasen contains records for roughly 40,000 active users and about 160,000 former users. These figures make up the upper estimate of 200,000 potentially affected people.
What was in the system
For current users, the exposed data may include Danish civil registration numbers, known as CPR numbers. Denmark issues these personal identification numbers to residents and uses them across public and private services. Full names, home addresses and profile pictures may also have been exposed.
Employment-related details were stored as well. These include work email addresses, job titles, office locations and other information tied to a person's role at the university.
The system also held next of kin data. Where active users had provided it, the dataset contained the names, relationships and phone numbers of their emergency contacts.
Former users are somewhat less exposed. DTU says home addresses, profile pictures and next of kin details for people who have left the university are deleted automatically after six months.
"This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected," said University Director Bjarke Bak Christensen.
"Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take," he added.
The university warns that criminals could use the stolen CPR numbers and other personal details for identity fraud, or to make phishing messages more believable.
Gaps in direct notification
DTU will contact affected individuals through e-Boks, the official digital mailbox it uses to send documents and notices to students and staff.
Not everyone will get a message, though. All current and former employees will be notified, but only some current and former students whose CPR numbers DTU holds will be reached this way.
"DTU only holds CPR numbers for a small number of guests and external partners and does not hold CPR numbers for next of kin whose contact details have been registered in DTUBasen," the university said.
To fill that gap, DTU made the incident public and is asking people to pass the notice on to former employees, students, guests and external partners. Anyone who has been an employee, student, guest or external partner of the university since 2003 may be affected.
Advice for those affected
DTU recommends caution with emails, text messages and phone calls from people who seem to know about a person's link to the university or who reference their personal details.
Other recommendations include:
- not sharing passwords or sensitive data in replies to unexpected messages
- treating sudden authentication requests or unexpected logins as suspicious
- changing passwords on any other services that reuse the DTU account credentials
- placing a credit alert on the affected CPR number
Why It Matters
The DTU incident is another sign that education institutions sit on deep archives of personal data that rarely shrink. A single IAM system holding two decades of records turned one set of stolen login details into a potential exposure of 200,000 people. That pattern resembles the recent Frontline Education breach, where school staff identifiers were exposed.
The entry point also deserves attention. DTU says the attacker simply logged in with compromised credentials. This suggests that access to central identity systems may not have been protected strongly enough to stop a valid but stolen login. Stolen and leaked credentials remain a common way in. The scale of the problem is clear from research showing still-valid credentials sitting in public code repositories.
For readers, the most immediate risk is likely targeted social engineering rather than mass fraud. Attackers who know a victim's name, address, job title and next of kin can write very convincing lures. The inclusion of emergency contacts is especially troubling, because it pulls people who never had any relationship with DTU into the incident.
DTU's retention policy for former users limited some of the damage. It is worth asking, though, why CPR numbers and names of people who left years ago were still accessible through the same system.
It is worth watching whether DTU can eventually say what data was actually taken. Another open question is whether the stolen records surface on criminal forums or leak sites. Organisations running similar IAM platforms may want to review how much historical data they keep and how access to it is protected.
