DTU breach may have exposed data of up to 200,000 users
The Technical University of Denmark disclosed that attackers used compromised credentials to access DTUBasen, its identity and access management system, downloading over two decades of user data. The system holds records for roughly 40,000 active users and 160,000 former users, including Danish civil registration numbers, addresses, profile pictures and next-of-kin contact details. DTU says it cannot yet determine exactly what data was taken or how many people are affected.
GoKawiil's interpretation of the reporting above, not reported fact.
The exposure of CPR numbers and family contact details raises the risk of identity fraud and more convincing phishing attempts, according to DTU's own warning. The incident highlights how identity management systems holding decades of historical data can become high-value targets, especially when retention policies allow old records to persist for years.
- Up to 200,000 current and former users may be affected
- Exposed data includes CPR numbers, addresses, photos and next-of-kin details
- DTU is notifying affected individuals via Denmark's e-Boks system
YubiKey 5 NFC Security Key — Credential-based breaches like the one at DTU highlight why passwords alone aren't enough to protect sensitive accounts. A YubiKey adds hardware-based two-factor authentication, making it far harder for attackers to log in even if they've stolen your password. It's a simple, durable way to lock down university, work, and personal accounts against exactly this kind of intrusion.
See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-10-03
Published there as: “Danish university DTU breach exposes data of up to 200,000 people”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.