The Technical University of Denmark (DTU) has disclosed a breach of its identity and access management platform, DTUBasen, that may have exposed personal records belonging to as many as 200,000 current and former students, staff, and partners.
What happened
According to the university, an attacker signed in to DTUBasen using stolen login credentials and exported a large volume of data before being detected. Because the system has been in continuous use for more than two decades, the exposure potentially reaches back to 2003 and covers roughly 40,000 active users alongside about 160,000 former ones. DTU says it has not yet been able to establish exactly which records were viewed or downloaded.
The data at risk for current members of the university community includes Danish national ID numbers (CPR), full names, home addresses, profile photos, work email addresses, job titles, and office locations. Where it had been supplied, DTUBasen also held the names, relationships, and phone numbers of users' next of kin. For former users, DTU notes that home address, photo, and next-of-kin details are purged automatically after six months, which should limit — but not eliminate — the exposure for that group.
Why it matters
CPR numbers underpin identity verification across Denmark's banking, healthcare, and government services. Combined with names, addresses, and workplace details, they give criminals most of what they need to commit identity fraud or craft convincing phishing and impersonation attempts against the people affected — or against DTU itself.
The incident is also a reminder that identity and access management systems are high-value targets precisely because they centralize decades of records in one place. A single compromised credential was enough to reach a system holding sensitive data on hundreds of thousands of people.
What to do
Anyone who has been a student, employee, guest, or external partner of DTU since 2003 should treat this disclosure as relevant to them, even without a direct notification — DTU says it cannot reach every affected person individually and is relying partly on public disclosure to do so.
- Be skeptical of unexpected emails, texts, or calls that reference a connection to DTU or appear to know personal details about you.
- Never share passwords or sensitive information in response to unsolicited messages, and treat sudden login or authentication requests as suspicious.
- Change passwords on any other accounts that reuse DTU credentials.
- Consider a credit or national-ID fraud alert where available, given the exposure of CPR numbers.
Organizations running large identity platforms should take the parallel lesson: credential-based access to IAM systems deserves the same scrutiny as access to the underlying data — strong authentication, anomaly detection on bulk exports, and clear retention limits for sensitive fields like next-of-kin contacts.
