The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.
The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management system, allowing access to more than two decades of user data. The breach may affect up to 200,000 current and former users, including students, employees, guests and external partners.
How the breach happened
According to DTU’s disclosure, threat actors compromised DTU profiles and used them to access DTUBasen, which contains personal data dating back to 2003. The university confirmed that it cannot currently determine precisely what information was downloaded or how many people have been affected.
The database holds records of approximately 40,000 active users and around 160,000 former users, all of whom may have been caught up in the incident.

What data was potentially exposed
Potentially exposed information for current users includes Danish civil registration numbers (CPR), full names, home addresses and profile pictures, as well as work email addresses, job titles, office locations and other employment-related details.
The dataset also contained the names, relationships and telephone numbers of users’ next of kin, where provided by active users. For former users, home addresses, profile pictures and next-of-kin information are automatically deleted after six months, but DTUBasen retains CPR numbers and full names indefinitely.
DTU warns that cybercriminals could use the exposed CPR numbers and other personal data for identity fraud and to make phishing attacks more convincing.
University response
University Director Bjarke Bak Christensen called it a serious attack on DTU, saying the university deeply regretted the uncertainty it was causing for the people whose information may have been affected. He said the university’s first priority had been to establish the extent of the attack, limit its consequences, and ensure those affected were notified and knew what steps to take.
The university says potentially impacted individuals will be notified through e-Boks, the official digital mailbox system DTU uses for documents and notices to students and staff. However, not all affected people can be contacted directly — so DTU has issued a public notice and is urging people to share it with former employees, students, guests and external partners.
Anyone who has been an employee, student, guest or external partner of DTU since 2003 may be affected.

What affected people should do
DTU is urging anyone connected to the university since 2003 to remain alert for suspicious messages, avoid approving unexpected login requests, and change passwords on any other services where they reused their DTU password. The university also recommends considering a credit alert against the affected CPR number, and cautions against disclosing passwords or sensitive information in replies to unexpected communications.
DTU works with the Danish Armed Forces and the defence industry on drone technology and has a significant defence and security research programme, although there is currently no indication that the attack was connected to this work. The investigation remains ongoing, and the university says it will provide more information as soon as possible.
FAKTA: The DTU data breach
- Hackers accessed DTU’s identity system, DTUBasen, using compromised credentials and downloaded a large amount of data.
- Up to 200,000 current and former users may be affected; data goes back to 2003.
- The database holds around 40,000 active users and 160,000 former users.
- Exposed data may include CPR numbers, names, addresses, profile photos, work emails and next-of-kin details.
- DTU will notify most affected people via e-Boks and has issued a public notice for others.
- Affected people are advised to watch for phishing, change reused passwords and consider a CPR credit alert.
Conclusion
The DTU breach is one of the largest data incidents to hit a Danish educational institution, with highly sensitive CPR numbers among the data at risk. With the university unable to say exactly whose data was taken, vigilance is the main defence for the up to 200,000 people in DTUBasen’s records.



































