DTU Cyberattack Exposes Data of Up to 200,000 Students and Staff

The Technical University of Denmark says attackers breached its identity system and downloaded personal data potentially affecting up to 200,000 current and former users.
DTU logo overtop red abstract background

The Technical University of Denmark has confirmed a major data breach after attackers compromised user profiles, gained access to the university’s identity and access management system and downloaded a large amount of data.

Information belonging to as many as 200,000 current and former users could be affected, including students, employees, guests and external partners. The potentially exposed information dates back to 2003 and includes Danish civil registration numbers, known as CPR numbers.

DTU disclosed the cyberattack on Oct. 2 and said its incident response team has contained the intrusion. External specialists are assisting with the investigation.

The university cannot determine precisely what information the attackers downloaded or exactly how many people were affected.

“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected,” University Director Bjarke Bak Christensen said in the university’s official breach notification.

Attackers compromised DTU profiles

DTU said unauthorized individuals compromised university profiles and then used that access to reach DTUBasen, the university’s identity and access management system.

Once inside, the attackers downloaded what DTU described as a large amount of data.

DTUBasen contains information on approximately 40,000 active users and another 160,000 former users, creating a potential exposure population of around 200,000 people.

DTU has not disclosed how the initial user profiles were compromised. It also has not publicly identified a vulnerability, malware family or other specific technique used to obtain the accounts.

No threat actor has been publicly attributed to the attack.

CPR numbers and personal information potentially exposed

The information at risk varies depending on whether an individual is a current or former DTU user.

For active users, potentially affected information includes:

  • Danish CPR numbers
  • Full names
  • Home addresses
  • Profile photographs
  • Work email addresses
  • Job titles and office locations
  • Other work-related information
  • Names, relationships and telephone numbers of registered next of kin

Former users face a somewhat different exposure. DTU automatically deletes their home addresses, profile photographs and next-of-kin information after 6 months, but DTUBasen continues to retain information including CPR numbers and full names.

The affected population could include anyone who has been a DTU employee, student, guest or external partner since 2003.

DTU stressed that it cannot determine which specific records were downloaded. The presence of information in DTUBasen therefore does not establish that every listed data type was stolen for every potentially affected individual.

National identification data raises fraud risk

The potential exposure of CPR numbers makes the incident particularly sensitive.

A CPR number is Denmark’s civil registration identifier and is used across public and private services. DTU warned that CPR numbers combined with other exposed personal information could potentially be used for identity fraud.

The stolen information could also help attackers construct more convincing phishing and social engineering attempts by incorporating legitimate information about a victim or their connection to the university.

People with protected names and addresses face an additional concern. DTU warned that disclosure of protected information could increase the risk of unwanted contact, being located or other forms of harassment.

The university is advising potentially affected users to remain alert for suspicious emails, text messages and telephone calls, particularly communications in which the sender appears to know legitimate information about the recipient.

DTU is also advising users not to approve unexpected authentication requests and to change passwords on other services if they reused their DTU password.

DTU recommends credit alerts

Because CPR numbers may have been exposed, DTU is recommending that affected individuals consider registering a credit alert against their CPR number through Denmark’s Borger.dk government service.

The measure can help warn lenders that additional identity verification should be performed before granting credit in the person’s name.

DTU plans to directly notify current and former employees and almost all current and former students for whom it holds a CPR number through Denmark’s e-Boks digital mailbox system.

Direct notification is more difficult for some other affected groups. DTU said it only holds CPR numbers for a small number of guests and external partners and does not hold CPR numbers for next of kin whose contact information was entered into DTUBasen.

The university therefore issued a public breach notification to help reach people it may be unable to contact individually.

Authorities investigating the breach

DTU has reported the incident to the Danish Data Protection Agency and referred the matter to relevant authorities for further investigation.

The university is simultaneously investigating the intrusion with external cybersecurity specialists.

While the attack has been contained, significant questions remain about the intrusion, including when attackers first gained access, how the initial DTU profiles were compromised and exactly which information was removed from DTUBasen.

DTU has not publicly attributed the attack to a cybercriminal, ransomware operation or state-backed threat actor, and its disclosure does not mention an extortion demand.

The university said its investigation and the authorities’ investigation remain ongoing and that it will provide additional information as significant findings become available.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →