DTU breach exposes CPR numbers on up to 200,000 people
Attackers used stolen credentials to raid DTU's DTUBasen identity system, exposing CPR numbers and personal data on up to 200,000 current and former users dating to 2003.
The Technical University of Denmark (DTU) says attackers logged into DTUBasen, its identity and access management system, with compromised credentials and downloaded a dataset spanning two decades. Up to 200,000 current and former users may be affected. The data includes Danish civil registration numbers (CPR). No group has claimed the intrusion.
What's affected
Per DTU's own breach notification, published 2 October 2026, DTUBasen holds records on roughly 40,000 active users and 160,000 former users — students, employees, guests, and external partners going back to 2003. The exposed fields may include:
- CPR number, full name, home address, and profile picture
- Work email, job title, office location, and other work-related data
- Name, relationship, and phone number of registered next of kin
DTU says it "cannot determine precisely" which records were taken. The university has reported the case to Datatilsynet, Denmark's data protection authority. Coverage at BleepingComputer and The Copenhagen Post matches the university's figures.
How it happened
This was not a software vulnerability. DTU says the attackers used compromised DTU profiles — valid credentials — to authenticate to DTUBasen and pull data at scale. No CVE applies, and DTU has not disclosed how the credentials were obtained. The IT incident response team says it has contained the activity and brought in external specialists to scope it.
The CPR number is the load-bearing detail. It is a lifelong national identifier used across Danish banking, health, and government services; combined with name, address, and next-of-kin data, it is a ready-made kit for identity fraud and highly credible phishing.
Attribution
Unattributed. DTU described the intruders only as unauthorized persons and named no actor; no cybercrime group has taken credit. We won't invent one.
What to do today
- If you've been affiliated with DTU since 2003, assume your CPR number is in this set. Watch your official e-Boks mailbox — DTU is notifying affected individuals there.
- Treat inbound "DTU" or authority messages as suspect. Attackers holding CPR plus address and next-of-kin can craft convincing lures. Verify through known channels, not links in the message.
- If you run an IAM or directory system, this is the reminder that valid credentials defeat perimeter controls. Check for anomalous bulk reads/exports, enforce MFA on admin and self-service portals, and alert on single accounts pulling full-directory datasets.
- Rotate any credentials reused against DTU services, and watch for CPR-linked abuse if you process Danish identity data.
Context
This is the second large Danish-adjacent public-sector exposure to land on our desk recently, and it rhymes with the wave of education-sector breaches — see our writeup of the Frontline Education incident that exposed school-district employee data. Universities are a recurring soft target: sprawling identity stores, decades of retained records, and thousands of standing accounts that make a single phished login enough to walk off with a population-scale dataset. The failure here wasn't an unpatched box — it was that one valid login could read 23 years of CPR numbers at once.