Skip to content
InYourGeek
visiteur@inyourgeek — shell
↹ compléter↑↓ historique⏎ ouvrirhelp
FR
Security· 3 min read

Technical University of Denmark breach exposes up to 200,000 people

Attackers used compromised credentials to break into the Technical University of Denmark's identity management system and downloaded a large amount of data. Anyone who has been through the university since 2003 may be affected, including employees' relatives.

A university campus building at dusk, with a padlock icon overlaid on a database of personal identity records

On Friday, the Technical University of Denmark (DTU) announced a breach of DTUBasen, its identity and access management system. Bleeping Computer reported the news on 3 October 2026. According to the university, the attacker logged in with compromised credentials and then downloaded a large volume of data covering more than twenty years of users. The facts reported here come from the institution’s own statement, as relayed by that single outlet.

DTU says it cannot determine exactly which information was taken, or how many people are affected. The figure of 200,000 reflects what the database holds: nearly 40,000 active users and around 160,000 former users.

What DTUBasen held

For current users, a wide range of data may have been exposed. This includes the Danish civil registration number (CPR), full name, home address and profile photo. Work-related information comes on top of that: work email address, job title, office location and other employment details.

The database also held data on people who never had any direct connection with the university. Where an active user had provided them, it stored the name, relationship and phone number of an emergency contact.

Former users are partly less exposed. According to DTU, their home address, photo and next-of-kin details are deleted automatically six months after they leave. Their name and the records tied to their time at the institution, however, remain in scope.

Why an identity system is a prime target

An identity and access management system exists to establish who is who within an organisation, and what each person is allowed to access. It therefore has to know every employee, student, guest and partner, with enough information to identify each of them unambiguously and to reach them. That is why DTUBasen combined civil identity data, contact details, internal organisational information and emergency contacts.

For an attacker, this means a single entry point to an entire population, rather than data scattered across several services. In this case, one login with valid credentials was enough to reach more than two decades of users. The university warns that CPR numbers and the other personal data exposed can be used for identity theft. They can also make phishing attempts more convincing, since the sender may know the target’s job title, office or the name of a relative.

Not everyone will be notified directly

Affected people will be notified through e-Boks, the official digital mailbox DTU uses with its students and staff. The university is contacting all its current and former employees. However, it will not be able to reach all of its students, current or former. It also explains that it holds the CPR number of only a small number of guests and external partners, and never that of relatives registered as emergency contacts.

The announcement was made public to close that gap. DTU is asking for it to be passed on to former employees, students, guests and external partners. Anyone who has held any of these roles since 2003 may be affected.

What the university recommends

If you have been through DTU, the institution advises you to be wary of emails, text messages and calls from people who appear to know about your connection with the university or to hold information about you. Do not share passwords or sensitive information in response to an unexpected message. Treat any authentication request or login prompt that appears without reason as suspicious.

DTU also recommends changing the password on any other service where you use the same credentials as for your DTU account, and placing a credit alert on your CPR number.

The breach began with a single compromised credential. Part of its consequences falls on people whose only link to the university is having been listed as someone’s emergency contact.

Sources (1)

Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.