NEWS

Danish University DTU Breach Exposes Data of Up to 200,000 People

Hackers breached DTU's DTUBasen identity system using stolen credentials, exposing CPR numbers, addresses, and next-of-kin data for up to 200,000 people.

Dylan H.

News Desk

October 3, 2026
6 min read
Danish University DTU Breach Exposes Data of Up to 200,000 People

DTU Discloses Breach of Identity System Affecting Up to 200,000 People

The Technical University of Denmark (DTU) disclosed on Friday, October 2, 2026, that attackers used compromised credentials to break into DTUBasen, the university's identity and access management (IAM) system, and downloaded a large volume of personal data. DTU says the exposure could affect up to 200,000 current and former users — roughly 40,000 active users and 160,000 former users, including staff, students, guests, and external collaborators dating back to 2003.


Breach Details

AttributeValue
OrganizationTechnical University of Denmark (DTU)
System BreachedDTUBasen (identity and access management / rights system)
Attack VectorCompromised credentials on multiple DTU user profiles
First DetectedSeptember 20, 2026 (per DTU IT director Mads Henrik Bang)
Attack PatternOccurred in several waves over time
ContainedFriday morning, October 2, 2026
Publicly DisclosedOctober 2, 2026
Individuals Potentially AffectedUp to ~200,000 (~40,000 active, ~160,000 former users)
Data TimeframeRecords dating back to 2003
AttributionNot identified; investigation ongoing
Regulatory NotificationReported to Datatilsynet (Danish Data Protection Agency)

What Happened

Attack Timeline

DTU's IT director said the intrusion unfolded in several waves, with the earliest activity first detected on September 20, 2026. Attackers compromised multiple DTU user profiles and used the resulting access to log into DTUBasen, the identity and access management system that underpins authentication and rights management across the university. DTU says the attack was fully contained on the morning of October 2, after which the university notified Danish authorities and began informing affected individuals.

DTU has stated it cannot "determine precisely what information was downloaded or how many people have been affected," which is why it framed the scope as "up to" 200,000 rather than a confirmed figure.

What Data Was Exposed

Because DTUBasen has served as the university's central identity store since 2003, the exposed dataset spans more than two decades of records. For active users, the potentially exposed data includes:

  • Danish civil registration numbers (CPR)
  • Full names, home addresses, and profile pictures
  • Work email addresses, job titles, and office locations
  • Next of kin names, relationships, and telephone numbers (where provided)

For former users, DTU noted that home addresses, profile pictures, and next-of-kin details are automatically purged from DTUBasen six months after a person leaves the university — meaning the exposure for that group is more likely limited to core identity data such as names and CPR numbers tied to historical records.

Who Is Affected

The affected population spans employees, students, guests, and external partners who have had an account in DTUBasen since 2003, split roughly between 40,000 active users and 160,000 former users.


Impact Assessment

Impact AreaDescription
Identity Theft RiskExposure of CPR numbers combined with names and addresses creates a strong basis for identity fraud in Denmark, where CPR numbers function as a master identifier for banking, healthcare, and government services.
Phishing / Social EngineeringNext-of-kin names, relationships, and phone numbers could let attackers craft highly convincing phishing or vishing attempts impersonating victims or their relatives.
Scope of UncertaintyDTU's inability to confirm exactly what was downloaded or how many people are affected complicates both individual risk assessment and the university's regulatory response.
Sector-Wide ExposureSecurity researchers note universities often run legacy IAM infrastructure holding large volumes of personal data, making higher education a persistent target.
Regulatory ExposureThe breach has been reported to Datatilsynet and referred to relevant authorities, which may result in a formal GDPR investigation given the scale and sensitivity of the data involved.

Cybersecurity professor Jens Myrup Pedersen rated the incident roughly 8 out of 10 in severity, noting Denmark had not seen a breach of comparable scale since the mid-2010s. He also pointed to a broader structural issue: many universities "hold a very large amount of personal data" while running older systems that may not meet 2026-level security expectations.


Recommendations

For Affected Individuals

  1. Treat unexpected login or authentication requests as suspicious — do not approve MFA prompts or login confirmations you did not initiate.
  2. Change your DTU account password, and change the password on any other account where you reused the same credentials.
  3. Watch for phishing attempts that reference your real name, job title, office location, or next-of-kin details — the leaked data makes these messages far more convincing.
  4. Consider a credit/fraud alert on your CPR number; Danish residents with protected identities can set up credit warnings via Borger.dk.
  5. Monitor for unusual activity tied to your CPR number across banking, healthcare, and government services.

For DTU and Higher-Education IT Teams

  • Audit and rotate credentials across all accounts with access to centralized IAM systems, not just those confirmed compromised.
  • Enforce phishing-resistant MFA on IAM administration and any account capable of bulk data access or export.
  • Modernize legacy identity stores — systems like DTUBasen that have accumulated two decades of retained data represent an outsized target; apply stricter data-retention limits for former users.
  • Deploy anomaly detection on IAM query/export volume so a "large amount of data" being downloaded triggers alerting long before public disclosure becomes necessary.

For Security Teams at Other Institutions

  • Inventory what personal data your IAM system retains, especially historical records for former users, and shorten retention windows where legally possible.
  • Segment IAM administrative access from general authentication flows so a single set of compromised credentials cannot reach bulk export functionality.
  • Prepare breach communication plans in advance — DTU's use of e-Boks plus public disclosure to reach otherwise unreachable former users is a practical model for multi-channel notification.

Key Takeaways

  1. Attackers used compromised credentials, not a software exploit, to access DTU's DTUBasen identity and access management system.
  2. The breach was first detected on September 20, 2026, unfolded in multiple waves, and was contained on October 2, 2026.
  3. Up to 200,000 people — roughly 40,000 active and 160,000 former DTU users — may have had data exposed, spanning records back to 2003.
  4. Exposed data for active users includes CPR numbers, addresses, profile pictures, employment details, and next-of-kin contact information.
  5. DTU has not identified who is responsible and admits it cannot confirm the exact scope of what was downloaded.
  6. The incident has been reported to Datatilsynet and referred to authorities, and an independent expert rated its severity at roughly 8 out of 10 — the largest Danish breach in years.

Sources