DTU Discloses Breach of Identity System Affecting Up to 200,000 People
The Technical University of Denmark (DTU) disclosed on Friday, October 2, 2026, that attackers used compromised credentials to break into DTUBasen, the university's identity and access management (IAM) system, and downloaded a large volume of personal data. DTU says the exposure could affect up to 200,000 current and former users — roughly 40,000 active users and 160,000 former users, including staff, students, guests, and external collaborators dating back to 2003.
Breach Details
| Attribute | Value |
|---|---|
| Organization | Technical University of Denmark (DTU) |
| System Breached | DTUBasen (identity and access management / rights system) |
| Attack Vector | Compromised credentials on multiple DTU user profiles |
| First Detected | September 20, 2026 (per DTU IT director Mads Henrik Bang) |
| Attack Pattern | Occurred in several waves over time |
| Contained | Friday morning, October 2, 2026 |
| Publicly Disclosed | October 2, 2026 |
| Individuals Potentially Affected | Up to ~200,000 (~40,000 active, ~160,000 former users) |
| Data Timeframe | Records dating back to 2003 |
| Attribution | Not identified; investigation ongoing |
| Regulatory Notification | Reported to Datatilsynet (Danish Data Protection Agency) |
What Happened
Attack Timeline
DTU's IT director said the intrusion unfolded in several waves, with the earliest activity first detected on September 20, 2026. Attackers compromised multiple DTU user profiles and used the resulting access to log into DTUBasen, the identity and access management system that underpins authentication and rights management across the university. DTU says the attack was fully contained on the morning of October 2, after which the university notified Danish authorities and began informing affected individuals.
DTU has stated it cannot "determine precisely what information was downloaded or how many people have been affected," which is why it framed the scope as "up to" 200,000 rather than a confirmed figure.
What Data Was Exposed
Because DTUBasen has served as the university's central identity store since 2003, the exposed dataset spans more than two decades of records. For active users, the potentially exposed data includes:
- Danish civil registration numbers (CPR)
- Full names, home addresses, and profile pictures
- Work email addresses, job titles, and office locations
- Next of kin names, relationships, and telephone numbers (where provided)
For former users, DTU noted that home addresses, profile pictures, and next-of-kin details are automatically purged from DTUBasen six months after a person leaves the university — meaning the exposure for that group is more likely limited to core identity data such as names and CPR numbers tied to historical records.
Who Is Affected
The affected population spans employees, students, guests, and external partners who have had an account in DTUBasen since 2003, split roughly between 40,000 active users and 160,000 former users.
Impact Assessment
| Impact Area | Description |
|---|---|
| Identity Theft Risk | Exposure of CPR numbers combined with names and addresses creates a strong basis for identity fraud in Denmark, where CPR numbers function as a master identifier for banking, healthcare, and government services. |
| Phishing / Social Engineering | Next-of-kin names, relationships, and phone numbers could let attackers craft highly convincing phishing or vishing attempts impersonating victims or their relatives. |
| Scope of Uncertainty | DTU's inability to confirm exactly what was downloaded or how many people are affected complicates both individual risk assessment and the university's regulatory response. |
| Sector-Wide Exposure | Security researchers note universities often run legacy IAM infrastructure holding large volumes of personal data, making higher education a persistent target. |
| Regulatory Exposure | The breach has been reported to Datatilsynet and referred to relevant authorities, which may result in a formal GDPR investigation given the scale and sensitivity of the data involved. |
Cybersecurity professor Jens Myrup Pedersen rated the incident roughly 8 out of 10 in severity, noting Denmark had not seen a breach of comparable scale since the mid-2010s. He also pointed to a broader structural issue: many universities "hold a very large amount of personal data" while running older systems that may not meet 2026-level security expectations.
Recommendations
For Affected Individuals
- Treat unexpected login or authentication requests as suspicious — do not approve MFA prompts or login confirmations you did not initiate.
- Change your DTU account password, and change the password on any other account where you reused the same credentials.
- Watch for phishing attempts that reference your real name, job title, office location, or next-of-kin details — the leaked data makes these messages far more convincing.
- Consider a credit/fraud alert on your CPR number; Danish residents with protected identities can set up credit warnings via Borger.dk.
- Monitor for unusual activity tied to your CPR number across banking, healthcare, and government services.
For DTU and Higher-Education IT Teams
- Audit and rotate credentials across all accounts with access to centralized IAM systems, not just those confirmed compromised.
- Enforce phishing-resistant MFA on IAM administration and any account capable of bulk data access or export.
- Modernize legacy identity stores — systems like DTUBasen that have accumulated two decades of retained data represent an outsized target; apply stricter data-retention limits for former users.
- Deploy anomaly detection on IAM query/export volume so a "large amount of data" being downloaded triggers alerting long before public disclosure becomes necessary.
For Security Teams at Other Institutions
- Inventory what personal data your IAM system retains, especially historical records for former users, and shorten retention windows where legally possible.
- Segment IAM administrative access from general authentication flows so a single set of compromised credentials cannot reach bulk export functionality.
- Prepare breach communication plans in advance — DTU's use of e-Boks plus public disclosure to reach otherwise unreachable former users is a practical model for multi-channel notification.
Key Takeaways
- Attackers used compromised credentials, not a software exploit, to access DTU's DTUBasen identity and access management system.
- The breach was first detected on September 20, 2026, unfolded in multiple waves, and was contained on October 2, 2026.
- Up to 200,000 people — roughly 40,000 active and 160,000 former DTU users — may have had data exposed, spanning records back to 2003.
- Exposed data for active users includes CPR numbers, addresses, profile pictures, employment details, and next-of-kin contact information.
- DTU has not identified who is responsible and admits it cannot confirm the exact scope of what was downloaded.
- The incident has been reported to Datatilsynet and referred to authorities, and an independent expert rated its severity at roughly 8 out of 10 — the largest Danish breach in years.