The Technical University of Denmark (DTU) disclosed on Friday 2 October that attackers used compromised credentials to log into DTUBasen, its identity and access management (IAM) system, and downloaded a large amount of data potentially covering up to 200,000 people — nearly 40,000 active users and around 160,000 former users. DTU said it cannot determine precisely what information was downloaded or how many people were affected, but acknowledged the dataset includes Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses and job titles for current users, plus next-of-kin names, relationships and phone numbers where supplied. University Director Bjarke Bak Christensen called it "a serious attack on DTU" and said priority was establishing the extent, limiting consequences and notifying those affected. DTU warned the exposed CPR numbers could be used for identity fraud and targeted phishing. It is a first-party disclosure of a breach of a national technical university's central identity system, and a reminder of the outsized value of IAM databases to attackers.
| Attribute | Detail |
|---|---|
| Sector | Education |
| Date | 2026-10-04 |
| Source | BleepingComputer |
| Reliability | Tier 2 |