"This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected," says University Director Bjarke Bak Christensen.
How attackers reached DTUBasen
The Technical University of Denmark (DTU) reported that an attacker used compromised credentials to log into DTUBasen, the university’s identity and access management (IAM) system. That access allowed the intruder to download a "large amount of data" spanning more than two decades of records. DTU says it cannot "determine precisely what information was downloaded or how many people have been affected."
What DTUBasen contained
DTU provided specifics on the types of records stored in DTUBasen. For current users, potentially exposed fields include Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, office locations, and other employment-related details. The dataset also contained the names, relationships, and telephone numbers of users’ next of kin when those details were provided by active users.
The university says DTUBasen stores information for nearly 40,000 active users and around 160,000 former users, which is the basis for the estimate that information belonging to up to 200,000 people may have been exposed. DTU also notes that for former users certain items—home addresses, profile pictures, and next of kin information—are automatically deleted after six months.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadWho may be affected and how DTU will notify them
DTU will notify potentially impacted individuals through e-Boks, the official mailbox system it uses to share documents and notices with students and staff. The university says it will notify all current and former employees, but not all current and former students whose CPR numbers are held by DTU.
DTU clarified its records on CPR numbers: it "only holds CPR numbers for a small number of guests and external partners and does not hold CPR numbers for next of kin whose contact details have been registered in DTUBasen." Still, the organization urged broad circulation of the public disclosure to reach people it cannot contact directly.
DTU said anyone who has been an employee, student, guest, or external partner of the university since 2003 may be affected and should assume possible exposure until they are informed otherwise.
Practical risks: identity fraud, phishing, and next-of-kin exposure
The university warned that exposed CPR numbers and other personal data could be used for identity fraud or to make phishing attacks more convincing. DTU specifically recommends heightened caution with emails, text messages, and phone calls from individuals who appear to know about a person’s connection to DTU or who display personal information about them.
DTU advises recipients not to disclose passwords or other sensitive information in replies to unexpected communications, and to treat sudden authentication requests or logins as suspicious. The university also recommends changing passwords for any other services that use the same credentials as the DTU account and placing a credit alert on the affected CPR number.
What this means for employees, students, and next of kin
- Employees: DTU will notify all current and former employees; staff should monitor official e-Boks messages, rotate passwords where credentials were reused, and consider credit alerts tied to their CPR numbers.
- Students: Not all current and former students will receive direct notification even if their CPR is held by DTU; students who were affiliated since 2003 should check e-Boks and treat unexpected communications relating to DTU with skepticism.
- Next of kin: Where next-of-kin names, relationships, and phone numbers were provided by active users, those contacts may have had their details exposed despite not being primary DTU users—next of kin should be vigilant for unsolicited contact that references personal links to a DTU affiliate.
DTU said its immediate priorities have been to establish the extent of the attack, limit its consequences, and ensure those affected are notified and know what steps to take. The university's inability to determine precisely what was downloaded leaves a wide set of potential follow-on risks for exposed individuals, and DTU is urging broad awareness among everyone connected to the institution since 2003.




