Skip to main content

DTU Data Breach Exposes 200,000 User Records via IAM Compromise

4 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Data of up to 200,000 current and former DTU users potentially exposed, risking identity fraud.
  • DTU's DTUBasen identity and access management system was compromised via stolen credentials.
  • Users should change passwords, monitor for phishing, and consider credit alerts for exposed CPRs.

Advertisement

The Technical University of Denmark (DTU) has disclosed a significant data breach affecting an estimated 200,000 current and former users. Attackers gained unauthorized access to the university’s identity and access management (IAM) system, known as DTUBasen, by utilizing compromised credentials. This breach allowed the download of a substantial volume of user data, dating back more than two decades, raising serious concerns about identity fraud and targeted phishing campaigns, according to BleepingComputer.

Technical Details of the DTUBasen Compromise

The incident involved an attacker logging into DTUBasen, DTU’s centralized system for managing user identities and access, using credentials that had been previously compromised. The university has confirmed it cannot precisely determine the full extent of the downloaded information or the exact number of affected individuals. However, DTUBasen stores data for approximately 40,000 active users and 160,000 former users, indicating a broad potential impact.

For current users, the exposed information includes highly sensitive data such as Danish civil registration numbers (CPR), full names, home addresses, and profile pictures. Additionally, work-related details like email addresses, job titles, and office locations were compromised. Critically, if provided by active users, the dataset also contained names, relationships, and telephone numbers of users’ next of kin. For former users, while home addresses, profile pictures, and next of kin information are automatically purged after six months, other foundational identity data could still be exposed.

Potential Consequences and Risks

The exposure of CPR numbers, coupled with other personal identifiers, significantly increases the risk of identity fraud. Cybercriminals can leverage this data to open fraudulent accounts, apply for credit, or engage in other malicious activities impersonating the victims. Furthermore, the detailed personal and professional information can be used to craft highly convincing and sophisticated phishing attacks. These tailored attacks, often referred to as spear-phishing, are far more likely to succeed than generic attempts, as they exploit the victim’s known connections to DTU and specific personal details.

University Director Bjarke Bak Christensen acknowledged the gravity of the situation, stating, “This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected.” The university’s immediate priority has been to assess the scope of the attack and mitigate its consequences.

Actionable Recommendations and Mitigations for DTU Users

Given the sensitive nature of the exposed data, particularly Danish CPR numbers, current and former DTU employees, students, guests, and external partners who have been associated with DTU since 2003 are advised to take immediate precautions. Effectively mitigating DTU DTUBasen compromise risks requires proactive steps.

  • Password Hygiene: Immediately change passwords for any DTU-related accounts. If the same credentials were reused on other services, those passwords must also be changed without delay.
  • Vigilance Against Phishing: Be extremely cautious of unexpected emails, text messages, or phone calls that appear to know your connection with DTU or possess personal information about you. Do not disclose passwords or sensitive information in response to such communications. Treat any sudden requests for authentication or login as suspicious.
  • Monitoring for Identity Fraud: Individuals concerned about the exposure of their Danish university data exposure CPR numbers should consider placing a credit alert on their CPR number to monitor for unauthorized financial activity. Regularly review bank statements and credit reports for any suspicious transactions.
  • Information Sharing: DTU is notifying potentially impacted individuals via e-Boks. However, the university urges the public to share this disclosure with any former employees, students, guests, or external partners who may not be directly reachable, emphasizing the wide scope of this breach.

Related: ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign, SafePal Data Breach Exposes 39,798 Customer Order Details

Advertisement

Advertisement