A DTU cyberattack disclosed on Friday, 2 October, may have affected personal data linked to up to 200,000 current and former users of the Technical University of Denmark (DTU), including students, employees, guests and partners.
The university said in an official notice that hackers gained access to DTUBasen, its identity and access management system, and downloaded a large amount of data. DTU has contained the attack, but says it cannot yet determine exactly which information was extracted or how many people are affected.
Hackers gained access to DTU’s user database
According to DTU, the attackers compromised university profiles and used them to gain access to DTUBasen, which contains personal information dating back to 2003.
The system includes records on approximately 40,000 active users and 160,000 former users. Those potentially affected include current and former employees and students, as well as guests and external partners.
DTU has reported the breach to the Danish Data Protection Agency (Datatilsynet), while the university and external specialists are continuing to investigate the incident alongside the relevant authorities.
University Director Bjarke Bak Christensen described the incident as serious.
“This is a serious attack on DTU, and we deeply regret the uncertainty it creates for the people whose information may have been affected. Our first priority has been to determine the extent of the attack, limit its consequences and make sure that those affected are informed and know what to do.”
He said DTU would continue to provide information as the investigation produces further findings.
CPR numbers and addresses may be among the affected data
For active users, the information stored in the system can include Denmark’s civil registration number, known as the CPR number, as well as full names, home addresses and profile pictures.
DTUBasen can also contain work email addresses, job titles, office locations and other employment-related information. Where users have registered an emergency contact, the database may also include that person’s name, relationship to the user and telephone number.
For former users, home addresses, profile pictures and information about relatives are automatically deleted after six months. However, DTU says the database continues to store information including CPR numbers and full names.
The university has not established whether all these categories of information were actually downloaded by the attackers.
DTU warns of identity misuse and phishing
DTU says that if CPR numbers and other personal information have reached unauthorised parties, the data could potentially be used for identity fraud or make phishing attempts and other forms of misuse more convincing.
The university is therefore advising anyone who has worked, studied, visited or collaborated with DTU since 2003 to be particularly cautious about unexpected emails, text messages, phone calls and login requests.
People who have reused their DTU password on other services are being advised to change it. DTU also says potentially affected users can consider placing a credit warning on their CPR number.
Current and former employees, together with almost all current and former students for whom DTU has a CPR number, are being notified through Denmark’s digital mailbox system, e-Boks.
DTU cannot directly contact all guests, partners or relatives whose contact details may have been stored in the database, which is why it has also issued a public notification.
The investigation remains ongoing, and DTU says it will update its information as new significant findings become available.





