Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
AI Analysis
Technical Summary
Hackers gained unauthorized access to DTU's identity and access management system (DTUBasen) by using compromised credentials. This access allowed them to download a large amount of user data spanning over two decades. The affected data includes sensitive personal information such as CPR numbers, names, addresses, employment details, and next of kin information for nearly 40,000 active users and approximately 160,000 former users. Former users' sensitive data like home addresses and next of kin details are automatically deleted after six months, but the exact data exfiltrated remains undetermined. DTU is notifying affected current and former employees and some users via the official e-Boks system and has publicly disclosed the breach to reach others. The breach poses risks of identity fraud and targeted phishing attacks using the exposed personal data.
Potential Impact
The breach exposed sensitive personal and employment-related information of up to 200,000 individuals connected to DTU, including Danish civil registration numbers (CPR), which can be used for identity fraud. The exposure of next of kin data increases privacy risks. The compromised credentials allowed attackers to access and download data from the university's identity and access management system, potentially enabling further targeted phishing or social engineering attacks. The university cannot confirm the exact scope of data downloaded, increasing uncertainty for affected individuals.
Mitigation Recommendations
DTU is notifying affected individuals through the official e-Boks system where possible and has publicly disclosed the breach to reach others. Affected persons are advised to be vigilant against phishing attempts and social engineering attacks that may use the exposed personal data. They should avoid disclosing passwords or sensitive information in response to unexpected communications and treat sudden authentication requests with suspicion. Changing passwords for DTU accounts and any other services using the same credentials is recommended. Placing a credit alert on the affected CPR number is also advised. No official patch or fix applies as this is a breach due to compromised credentials rather than a software vulnerability.
Danish university DTU breach exposes data of up to 200,000 people
Description
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Hackers gained unauthorized access to DTU's identity and access management system (DTUBasen) by using compromised credentials. This access allowed them to download a large amount of user data spanning over two decades. The affected data includes sensitive personal information such as CPR numbers, names, addresses, employment details, and next of kin information for nearly 40,000 active users and approximately 160,000 former users. Former users' sensitive data like home addresses and next of kin details are automatically deleted after six months, but the exact data exfiltrated remains undetermined. DTU is notifying affected current and former employees and some users via the official e-Boks system and has publicly disclosed the breach to reach others. The breach poses risks of identity fraud and targeted phishing attacks using the exposed personal data.
Potential Impact
The breach exposed sensitive personal and employment-related information of up to 200,000 individuals connected to DTU, including Danish civil registration numbers (CPR), which can be used for identity fraud. The exposure of next of kin data increases privacy risks. The compromised credentials allowed attackers to access and download data from the university's identity and access management system, potentially enabling further targeted phishing or social engineering attacks. The university cannot confirm the exact scope of data downloaded, increasing uncertainty for affected individuals.
Defensive Guidance
DTU is notifying affected individuals through the official e-Boks system where possible and has publicly disclosed the breach to reach others. Affected persons are advised to be vigilant against phishing attempts and social engineering attacks that may use the exposed personal data. They should avoid disclosing passwords or sensitive information in response to unexpected communications and treat sudden authentication requests with suspicion. Changing passwords for DTU accounts and any other services using the same credentials is recommended. Placing a credit alert on the affected CPR number is also advised. No official patch or fix applies as this is a breach due to compromised credentials rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.9,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/","fetched":true,"fetchedAt":"2026-10-03T14:46:13.843Z","wordCount":814}
Threat ID: 6ac11535a43b0b3b89c9f914
Added to database: 10/03/2026, 14:46:13 UTC
Last enriched: 10/03/2026, 14:46:19 UTC
Last updated: 10/04/2026, 03:52:10 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.