← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

DTU data breach exposes personal information of up to 200,000 users

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • DTU's IAM system, DTUBasen, was breached.
  • Up to 200,000 users potentially affected.
  • Exposed data includes CPR numbers, names, addresses.
  • Next of kin data also potentially exposed.

Identity and Access Management System Compromised

The Technical University of Denmark (DTU) disclosed that its identity and access management (IAM) system, DTUBasen, was breached. Attackers used compromised credentials to gain unauthorized access and download a significant amount of data. The university confirmed it cannot precisely determine the extent of the downloaded information or the exact number of affected individuals.

Scope of Exposed Data

DTUBasen stores information for approximately 40,000 active users and 160,000 former users, totaling up to 200,000 individuals. For current users, potentially exposed data includes Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, and office locations. The dataset also contained names, relationships, and telephone numbers of users’ next of kin, if provided. For former users, home addresses, profile pictures, and next of kin information are automatically deleted after six months.

Potential Risks and University Response

DTU warns that the exposed CPR numbers and other personal data could be used by cybercriminals for identity fraud and to create more convincing phishing attacks. University Director Bjarke Bak Christensen stated that the priority is to assess the attack's extent, limit consequences, and notify affected individuals. Notifications will be sent via e-Boks, the official Danish digital mailbox system. While all current and former employees will be notified, not all current and former students with CPR numbers held by DTU will receive direct notifications. DTU holds CPR numbers for a small number of guests and external partners, but not for next of kin.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 20 stories · Oct 03

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Technical University of Denmark (DTU) experienced a data breach where hackers accessed its identity and access management system, potentially exposing data for up to 200,000 current and former users. The compromised data includes Danish civil registration numbers (CPR), names, addresses, and next of kin information, which could be used for identity fraud and phishing attacks.