grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

DTU Data Breach Exposes Data of Up to 200,000 People

DTU data breach
Published on
October 5, 2026

The Technical University of Denmark has warned current and former staff, students, guests and external partners that attackers may hold their personal data. The DTU data breach stretches back more than two decades and could touch as many as 200,000 people. Attackers logged into DTUBasen, the university's identity and access management system, using compromised credentials, then downloaded a large volume of records. DTU published its disclosure on 2 October after its incident response team contained the attack.

The university cannot say what the attackers took. It also cannot say how many people the theft covers, and that gap defines the entire response. DTUBasen holds records on roughly 40,000 active users and about 160,000 former ones, so DTU is now warning a population it cannot precisely identify.

What the DTU data breach exposed

For active users, the exposed records may include Danish civil registration numbers (CPR), full names, home addresses and profile pictures. They may also contain work email addresses, job titles, office locations and other employment details. Put together, that amounts to a near-complete identity profile for each person.

Former users sit in a marginally better position. DTU deletes home addresses, profile pictures and next-of-kin details six months after someone leaves. But CPR numbers and full names remain, so the DTU data breach still exposes the two most durable identifiers belonging to a student who graduated fifteen years ago.

Records reaching back to 2003

The dataset covers everyone connected to the university since 2003. Anyone who worked there, studied there, visited or partnered with DTU in that window may appear in it. That is an unusually long tail for a single incident, and it pulls in people who cut ties with the university years ago.

Compromised accounts opened the door

Attackers compromised DTU profiles and used those accounts to reach DTUBasen. Valid credentials carried them straight past the perimeter, so the initial access generated none of the noise an exploit would produce. From there they moved through a system that, by design, knows something about everyone.

That design made the DTU data breach so broad. An identity and access management platform sits at the centre of an organisation and maps every person to every entitlement. Compromise one account with enough reach into it, and the directory itself becomes the prize.

DTU's incident response team contained the attack and brought in external specialists to measure it. The university reported the DTU data breach to the Danish Data Protection Agency and referred the case to the relevant authorities. Those investigations continue.

Why CPR numbers raise the stakes

A CPR number follows a Danish resident for life. You cannot rotate it the way you rotate a password, and nobody reissues it after a leak the way a bank reissues a card. Once it circulates, it circulates permanently.

DTU warns that criminals could use the stolen CPR numbers for identity fraud. The same data also sharpens phishing considerably. A message quoting your correct CPR number, your old office location and your job title clears a credibility bar that generic phishing never reaches.

That is the quiet danger in the DTU data breach. Fraud built on this dataset arrives looking like routine administrative contact from an institution the recipient genuinely dealt with.

Next of kin pulled into the DTU data breach

Active users who registered emergency contacts handed over a name, a relationship and a phone number belonging to somebody else. Those records sat in DTUBasen too. So a spouse, a parent or an adult child who never set foot on campus may now sit in stolen data because of a relative's employment record.

DTU holds no CPR numbers for these contacts, which limits the damage. But it also holds no way to reach them. That is the widest edge of the DTU data breach: people with no connection to the university at all, exposed through someone else's profile.

How DTU is reaching affected people

Anyone caught in the DTU data breach will hear from the university through e-Boks, Denmark's official digital mailbox. Current and former employees receive a personal notice, as do almost all current and former students for whom DTU holds a CPR number. Those notifications went out as fast as the investigation allowed.

Guests and external partners present a harder problem, because the university holds CPR numbers for only a small number of them. Registered next of kin fall outside the notification system entirely. The public disclosure exists to cover those gaps, and DTU has asked recipients to pass it on to former colleagues and classmates.

Steps to take after the DTU data breach

DTU's guidance is practical, and it holds up even for peopleunsure of their exposure:

  • Treat unexpected emails, texts and calls with suspicion, particularly when the sender appears to know your DTU connection.
  • Never give out passwords or confidential details in response to an enquiry you did not initiate.
  • Reject login and authentication prompts you did not trigger yourself.
  • Change your password on any service where you reused your DTU credentials.
  • Consider registering a credit alert against your CPR number through Borger.dk.

People with name and address protection need extra care. If their details left DTUBasen, the risk shifts away from financial fraud and toward being located, contacted or harassed. DTU singled out this group deliberately.

What the DTU data breach means for other organisations

Universities attract attackers because they hold decades of personal records, serve a huge rotating population and run open networks by necessity. But the mechanics here travel well beyond higher education. Any organisation running an identity platform holds the same concentration of personal data behind the same single point of failure.

Two defences would have narrowed this. Phishing-resistant multi-factor authentication raises the cost of credential compromise sharply. Hard limits on which accounts can query or export directory records at scale cap the damage once an attacker gets inside.

Retention policy is the third lever. DTU deletes several fields six months after a user leaves, and that discipline measurably reduced what former users lost. Deleting more, sooner, would have reduced it further.

The DTU data breach will take weeks to map fully, and the university has promised updates as it learns more. For the people inside that dataset, though, the practical position is already settled. Assume the data is out, treat unsolicited contact as hostile, and lock down every account that ever shared a password with a DTU login.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.