Cyberattack on Denmark's DTU may have exposed personal data of up to 200,000 users
The Technical University of Denmark says hackers breached its DTUBasen identity system and downloaded large amounts of personal data dating back to 2003, potentially affecting up to 200,000 current and former users.

The Technical University of Denmark (DTU) has disclosed a serious cyberattack on its identity management system that may have exposed the personal data of up to 200,000 current and former users, including students, employees, guests and external partners.
In an official notification published on Friday 2 October, DTU said unauthorised persons compromised university profiles and used them to gain access to DTUBasen, its identity and access management system, and downloaded a large amount of data. The university says it has contained the attack but cannot yet determine exactly which information was extracted or how many people are affected.
DTUBasen holds records on approximately 40,000 active users and 160,000 former users, with personal data dating back to 2003. For active users, the system can store Denmark’s civil registration (CPR) number, full name, home address, profile picture, work email, job title, office location, and next-of-kin details where registered.
DTU has reported the breach to the Danish Data Protection Agency (Datatilsynet) and referred it to the relevant authorities, and is investigating alongside external specialists.
“This is a serious attack on DTU, and we deeply regret the uncertainty it creates for the people whose information may have been affected,” University Director Bjarke Bak Christensen said.
DTU warned that any exposed CPR numbers and personal data could be used for identity fraud or convincing phishing attempts, and urged anyone who has worked, studied, visited or collaborated with DTU since 2003 to be cautious of unexpected messages and login requests.
More on this topic: all Technology stories
