DTU data breach exposes CPR numbers of up to 200,000 users
Denmark's DTU said attackers used stolen credentials to breach its DTUBasen identity system, exposing CPR numbers and other personal data of up to 200,000 current and former users.
- Victim
- Technical University of Denmark (DTU)
- users
- 200.0K
On 2 October 2026, the Technical University of Denmark (DTU) β one of Europe's leading engineering universities β disclosed that attackers had broken into DTUBasen, its central identity and access management system, and downloaded a large volume of personal data. University Director Bjarke Bak Christensen called it "a serious attack on DTU" and said the institution deeply regretted the uncertainty it was causing for those whose information may have been affected.
According to DTU, the intruders compromised legitimate DTU user profiles and used that access to reach DTUBasen, which holds records dating back to 2003. The university said the incident may affect up to 200,000 current and former users β roughly 40,000 active accounts and about 160,000 former ones β spanning students, staff, guests and external partners. DTU stressed that it could not determine precisely which records were downloaded or the exact number of people impacted.
What was exposed
For current users, the potentially accessed data includes Danish civil registration (CPR) numbers, full names, home addresses, telephone numbers, profile photographs, work email addresses, job titles, office locations and, in some cases, contact details for next of kin. For former users, DTU said CPR numbers and full names remain in DTUBasen while other categories are generally purged after a retention period. A CPR number alone does not grant access to Danish public services β those require secondary authentication such as MitID β but its exposure alongside names and addresses sharply raises the risk of identity fraud and targeted phishing.
Response
DTU said it contained the attack with its internal incident-response team and external specialists, reported the breach to the Danish Data Protection Agency (Datatilsynet), and began notifying affected individuals through the national e-Boks digital-mail system. The university advised recipients to be alert for phishing, change their passwords, and consider registering a credit alert tied to their CPR number. The case was also referred to Denmark's national cybercrime unit, and the incident renewed warnings from security researchers that ageing university IT systems make the sector an attractive target.
Timeline
DTU discloses the breach, reports it to the Danish Data Protection Agency, and begins notifying affected individuals via e-Boks.
Sources
- dtu.dkhttps://www.dtu.dk/english/newsarchive/2026/10/cyberattack-on-dtu_notification-of-a-personal-data-breach
- cphpost.dkhttps://cphpost.dk/2026-10-02/life-in-denmark/dtu-data-breach-may-affect-personal-information-of-200000-current-and-former-users/
- cybernews.comhttps://cybernews.com/news/dtu-university-hacked-200000-people-potentially-exposed/