The Technical University of Denmark (DTU) disclosed that its identity and access management (IAM) system, DTUBasen, was breached. Attackers used compromised credentials to gain unauthorized access and download a significant amount of data. The university confirmed it cannot precisely determine the extent of the downloaded information or the exact number of affected individuals.
DTUBasen stores information for approximately 40,000 active users and 160,000 former users, totaling up to 200,000 individuals. For current users, potentially exposed data includes Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, and office locations. The dataset also contained names, relationships, and telephone numbers of users’ next of kin, if provided. For former users, home addresses, profile pictures, and next of kin information are automatically deleted after six months.
DTU warns that the exposed CPR numbers and other personal data could be used by cybercriminals for identity fraud and to create more convincing phishing attacks. University Director Bjarke Bak Christensen stated that the priority is to assess the attack's extent, limit consequences, and notify affected individuals. Notifications will be sent via e-Boks, the official Danish digital mailbox system. While all current and former employees will be notified, not all current and former students with CPR numbers held by DTU will receive direct notifications. DTU holds CPR numbers for a small number of guests and external partners, but not for next of kin.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Technical University of Denmark (DTU) experienced a data breach where hackers accessed its identity and access management system, potentially exposing data for up to 200,000 current and former users. The compromised data includes Danish civil registration numbers (CPR), names, addresses, and next of kin information, which could be used for identity fraud and phishing attacks.