Danish university DTU breach may expose CPR numbers of up to 200,000 people

Attackers used compromised accounts to access DTU's identity management system and download records going back to 2003, affecting up to 200,000 current and former users.

Danish university DTU breach may expose CPR numbers of up to 200,000 people

At a glance

  • Attackers used compromised DTU profiles to access DTUBasen, the university's identity and access management system, and downloaded a large volume of data.
  • Up to 200,000 people may be affected: about 40,000 active and about 160,000 former users, with records dating back to 2003.
  • Exposed data may include Danish CPR numbers, names, home addresses, profile pictures, work details and next-of-kin information.
  • DTU has notified the Danish Data Protection Agency and advises affected people to watch for phishing, change reused passwords and consider a credit alert.

The Technical University of Denmark (DTU) has disclosed a cyberattack on DTUBasen, its identity and access management system, in which unauthorized persons downloaded a large amount of data that may concern up to 200,000 current and former users. According to the university's breach notification, published on October 2, the exposed records include Danish civil registration (CPR) numbers and go back as far as 2003, making the incident one of the larger university data breaches reported in Europe this year.

What happened

DTU said it identified the breach on October 2. According to the notification, the attackers first compromised DTU user profiles and then used them to gain access to DTUBasen, which holds identity information on employees, students, guests and external partners. The university has not said when the intrusion began or who is behind it.

DTU acknowledged that it cannot determine precisely what information was downloaded or exactly how many people are affected. The university has reported the incident to the Danish Data Protection Agency (Datatilsynet) and handed the case to the relevant authorities for investigation, it said. As BleepingComputer reported, no threat actor has publicly claimed the attack.

"This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected," University Director Bjarke Bak Christensen said in the statement.

Who is affected

According to DTU, DTUBasen contains information on roughly 40,000 active users and about 160,000 former users. For current users, the data that may have been exposed includes:

  • CPR number, full name, home address and profile picture
  • Work email address, job title, office location and other work-related information
  • Next-of-kin details where registered, including name, relationship and phone number

For former users, DTU said CPR numbers and full names are retained, while home addresses, profile pictures and next-of-kin details are normally deleted automatically six months after a person leaves the university.

The CPR number is a lifelong personal identifier used across Danish public and private services, which makes its exposure particularly sensitive for identity fraud and targeted social engineering.

What to do

DTU urges current and former employees, students, guests and partners to:

  • Be alert to suspicious emails, text messages and calls that reference DTU or appear to come from the university
  • Never disclose passwords or sensitive information, and treat unexpected login or authentication requests as suspicious
  • Change passwords on any other services where the same credentials as the DTU account were used
  • Consider registering a credit alert on their CPR number via Borger.dk

Organizations that work with DTU should also expect phishing that abuses the stolen work details, such as job titles and office locations, to impersonate university staff. Because the attack started with compromised user profiles, the incident is another reminder of the value of phishing-resistant multi-factor authentication and close monitoring of access to central identity systems.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.