Breaking
Cyber CrimeDeveloping Story

DTU breach exposes 200k user records

Hackers accessed the Technical University of Denmark's identity system using compromised credentials, potentially exposing data of up to 200,000 people.

··2 hours ago·5 min read
A sunny campus scene with buildings and pathways
Photo by Allen Y on Unsplash

When attackers logged into DTUBasen, the Technical University of Denmark's identity and access management system, they didn't just open a door—they found a vault holding more than two decades of user data. The university now says information belonging to up to 200,000 people may have been exposed, a figure that includes both current and former members of its community.

The breach, disclosed on Friday, underscores a familiar weakness: even robust identity systems can fall when credentials are compromised. DTU has confirmed that the attacker used valid login details to access DTUBasen, granting them sweeping visibility into personal and employment records.

A system built on trust

DTUBasen is the university's central hub for managing digital identities. It stores information for nearly 40,000 active users and around 160,000 former users. That combined pool forms the basis for the 200,000 figure DTU now cites as potentially affected. The system has been accumulating data since at least 2003, meaning the breach reaches back through generations of students, staff, and partners.

According to DTU, the attacker downloaded a large amount of data, but the university cannot determine precisely what information was taken or exactly how many individuals are impacted. That uncertainty is itself a problem, leaving a wide swath of people in limbo.

What was exposed

For current users, the compromised data may include Danish civil registration numbers (CPR), full names, home addresses, and profile pictures. Also potentially exposed are work email addresses, job titles, office locations, and other employment-related details. Additionally, the dataset contained names, relationships, and telephone numbers of users' next of kin, when provided by active users.

For former users, the exposure is slightly different. DTU says that details about home addresses, profile pictures, and information about next of kin are automatically deleted after six months. That retention policy may have limited what was available for some former members, though the university has not specified how many records were affected by that cleanup.

University response and notification

DTU is notifying potentially impacted individuals through e-Boks, the official mailbox system it uses for sharing documents and notices with students and staff. The university says it will notify all current and former employees, but not all current and former students whose CPR numbers are held by DTU.

“DTU only holds CPR numbers for a small number of guests and external partners and does not hold CPR numbers for next of kin whose contact details have been registered in DTUBasen,” the organization says.

The public disclosure is part of DTU's effort to reach people it cannot contact directly. The university is urging recipients to share the notice with former employees, students, guests, and external partners. Anyone who has been an employee, student, guest, or external partner of DTU since 2003 may be affected.

“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected,” says University Director Bjarke Bak Christensen.

— Bjarke Bak Christensen, University Director at DTU

He added: “Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take.”

Risks for affected individuals

DTU warns that cybercriminals could use the exposed CPR numbers and other personal data for identity fraud and to make phishing attacks more convincing. The combination of a national ID number, address, and next-of-kin details gives attackers a rich set of tools for social engineering.

Those potentially affected are advised to be cautious of emails, text messages, and phone calls from individuals who appear to know about their connection with DTU or have access to personal information about them. The university stresses that passwords and sensitive information should never be disclosed in replies to unexpected communications.

  • 40,000 active users currently in DTUBasen
  • 160,000 former users still in the system
  • Up to 200,000 people may have been exposed
  • Data stretches back to 2003—more than two decades

Steps to take if you might be affected

DTU recommends changing passwords for any other services that use the same credentials as the DTU account. Reusing passwords across multiple sites amplifies the damage of any single breach.

The university also suggests placing a credit alert on the affected CPR number. A credit alert can help flag suspicious activity if criminals attempt to open accounts or take out loans using the stolen identity information.

Anyone who receives an unexpected authentication request or login prompt should treat it as suspicious. Attackers who already have some personal data may try to trick victims into approving access to other accounts.

The broader context of IAM attacks

Identity and access management systems have become a prime target for attackers because they centralize credentials and personal information. A single set of compromised credentials can unlock a treasure trove of data, as appears to have happened here.

DTU's case highlights the challenge of securing sprawling university environments, where users come and go, and where data retention policies vary between active and former members. Even with automatic deletion after six months for some records, the long tail of historical data remains a liability.

The university has not disclosed how the credentials were compromised or whether additional security measures are being implemented. It continues to investigate the extent of the breach.

Why this matters beyond DTU

For businesses and institutions, the DTU breach is a reminder that identity systems are not just administrative tools—they are high-value targets. A compromised IAM platform can expose not only current users but also former ones, widening the blast radius far beyond what many organizations anticipate.

The inclusion of next-of-kin data adds another layer of risk. When attackers can map relationships, they can craft more convincing phishing attempts that reference family members, making it harder for recipients to spot the fraud.

For individuals, the incident underscores the importance of password hygiene and vigilance. Reusing credentials across services is a common habit, but it turns one breach into many. Those who have been affiliated with DTU since 2003 should consider themselves potentially at risk and act accordingly.

As universities and enterprises continue to digitize their operations, the security of identity systems will remain a critical concern. This case shows that even a well-established institution with retention policies can face a wide-reaching data exposure when credentials fall into the wrong hands.

#data breach#dtu#identity management#denmark#compromised credentials#university

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories