The Technical University of Denmark (DTU) has disclosed a breach of its identity and access management system that may have exposed personal data belonging to as many as 200,000 current and former users.

According to the university, an attacker used compromised credentials to log into DTUBasen, DTU’s IAM platform, gaining access to more than two decades of stored user records. DTU says it cannot determine precisely what data was downloaded or exactly how many people were affected, but the system holds information on roughly 40,000 active users and around 160,000 former users.

What was exposed

For current users, the potentially compromised data includes Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, and office locations. The system also stored names, relationships, and phone numbers for next of kin when provided by active users.

DTU notes that for former users, home addresses, profile pictures, and next-of-kin information are automatically deleted after six months, limiting exposure for that group.

University Director Bjarke Bak Christensen called it a serious attack and said the institution’s priority has been to determine its scope, contain the damage, and notify affected individuals.

Notification gaps

DTU is notifying affected current and former employees directly through e-Boks, Denmark’s official digital mailbox system. However, the university says it will not be able to directly notify all current and former students whose CPR numbers may be held in the system, since CPR numbers are generally retained only for a small number of guests and external partners, not for students broadly.

Anyone who has been an employee, student, guest, or external partner of DTU since 2003 may be affected, and the university is asking the public to help spread the disclosure to reach those it cannot contact directly.

Recommended precautions

  • Treat unexpected emails, texts, or calls referencing a DTU connection with suspicion
  • Never share passwords or sensitive data in response to unsolicited messages
  • Be wary of unexpected authentication prompts or login requests
  • Change passwords on any other accounts that reuse DTU credentials
  • Place a credit alert on the affected CPR number

DTU warns that exposed CPR numbers and personal details could be used for identity fraud or to craft more convincing phishing campaigns.