Skip to content
Data breachContained

DTU data breach exposes CPR numbers of up to 200,000 users

Denmark's DTU said attackers used stolen credentials to breach its DTUBasen identity system, exposing CPR numbers and other personal data of up to 200,000 current and former users.

Victim
Technical University of Denmark (DTU)
users
200.0K

On 2 October 2026, the Technical University of Denmark (DTU) β€” one of Europe's leading engineering universities β€” disclosed that attackers had broken into DTUBasen, its central identity and access management system, and downloaded a large volume of personal data. University Director Bjarke Bak Christensen called it "a serious attack on DTU" and said the institution deeply regretted the uncertainty it was causing for those whose information may have been affected.

According to DTU, the intruders compromised legitimate DTU user profiles and used that access to reach DTUBasen, which holds records dating back to 2003. The university said the incident may affect up to 200,000 current and former users β€” roughly 40,000 active accounts and about 160,000 former ones β€” spanning students, staff, guests and external partners. DTU stressed that it could not determine precisely which records were downloaded or the exact number of people impacted.

What was exposed

For current users, the potentially accessed data includes Danish civil registration (CPR) numbers, full names, home addresses, telephone numbers, profile photographs, work email addresses, job titles, office locations and, in some cases, contact details for next of kin. For former users, DTU said CPR numbers and full names remain in DTUBasen while other categories are generally purged after a retention period. A CPR number alone does not grant access to Danish public services β€” those require secondary authentication such as MitID β€” but its exposure alongside names and addresses sharply raises the risk of identity fraud and targeted phishing.

Response

DTU said it contained the attack with its internal incident-response team and external specialists, reported the breach to the Danish Data Protection Agency (Datatilsynet), and began notifying affected individuals through the national e-Boks digital-mail system. The university advised recipients to be alert for phishing, change their passwords, and consider registering a credit alert tied to their CPR number. The case was also referred to Denmark's national cybercrime unit, and the incident renewed warnings from security researchers that ageing university IT systems make the sector an attractive target.

Timeline

  1. DTU discloses the breach, reports it to the Danish Data Protection Agency, and begins notifying affected individuals via e-Boks.

Sources

  1. dtu.dkhttps://www.dtu.dk/english/newsarchive/2026/10/cyberattack-on-dtu_notification-of-a-personal-data-breach
  2. cphpost.dkhttps://cphpost.dk/2026-10-02/life-in-denmark/dtu-data-breach-may-affect-personal-information-of-200000-current-and-former-users/
  3. cybernews.comhttps://cybernews.com/news/dtu-university-hacked-200000-people-potentially-exposed/

Related incidents

Data breachOngoing

FulcrumSec leaks Global Schools Foundation data, exposing 33,000+ children's and parents' passports

The extortion group FulcrumSec claimed it stole roughly 4.8 terabytes of data from Singapore-based Global Schools Foundation after exploiting database credentials left unchanged since a 2022 breach, leaking 33,088 passport numbers belonging to children and parents and around 9.4 million internal messages when ransom negotiations collapsed.

Victim
Global Schools Foundation