# DTU Data Breach Exposes 200,000 User Records via IAM Compromise

> The Technical University of Denmark (DTU) reports a data breach affecting up to 200,000 users, exposing sensitive data including CPR numbers.

- Published: 2026-10-03T18:55:05.000Z
- Severity: high
- Category: Data Breach
- Tags: Data Breach, Identity and Access Management, Identity Fraud, Phishing, DTU
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/
- Canonical: https://runtimerebel.com/blog/dtu-data-breach-exposes-200000-user-records-via-iam-compromise

## Key points

- Data of up to 200,000 current and former DTU users potentially exposed, risking identity fraud.
- DTU's DTUBasen identity and access management system was compromised via stolen credentials.
- Users should change passwords, monitor for phishing, and consider credit alerts for exposed CPRs.

The Technical University of Denmark (DTU) has disclosed a significant [data breach](/glossary#data-breach) affecting an estimated 200,000 current and former users. Attackers gained unauthorized access to the university's identity and access management ([IAM](/glossary#iam)) system, known as DTUBasen, by utilizing compromised credentials. This breach allowed the download of a substantial volume of user data, dating back more than two decades, raising serious concerns about identity fraud and targeted [phishing](/glossary#phishing) campaigns, according to [BleepingComputer](https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/).

## Technical Details of the DTUBasen Compromise

The incident involved an attacker logging into DTUBasen, DTU's centralized system for managing user identities and access, using credentials that had been previously compromised. The university has confirmed it cannot precisely determine the full extent of the downloaded information or the exact number of affected individuals. However, DTUBasen stores data for approximately 40,000 active users and 160,000 former users, indicating a broad potential impact.

For current users, the exposed information includes highly sensitive data such as Danish civil registration numbers (CPR), full names, home addresses, and profile pictures. Additionally, work-related details like email addresses, job titles, and office locations were compromised. Critically, if provided by active users, the dataset also contained names, relationships, and telephone numbers of users' next of kin. For former users, while home addresses, profile pictures, and next of kin information are automatically purged after six months, other foundational identity data could still be exposed.

## Potential Consequences and Risks

The exposure of CPR numbers, coupled with other personal identifiers, significantly increases the risk of identity fraud. Cybercriminals can leverage this data to open fraudulent accounts, apply for credit, or engage in other malicious activities impersonating the victims. Furthermore, the detailed personal and professional information can be used to craft highly convincing and sophisticated phishing attacks. These tailored attacks, often referred to as spear-phishing, are far more likely to succeed than generic attempts, as they [exploit](/glossary#exploit) the victim's known connections to DTU and specific personal details.

University Director Bjarke Bak Christensen acknowledged the gravity of the situation, stating, "This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected." The university's immediate priority has been to assess the scope of the attack and mitigate its consequences.

## Actionable Recommendations and Mitigations for DTU Users

Given the sensitive nature of the exposed data, particularly Danish CPR numbers, current and former DTU employees, students, guests, and external partners who have been associated with DTU since 2003 are advised to take immediate precautions. Effectively mitigating DTU DTUBasen compromise risks requires proactive steps.

*   **Password Hygiene:** Immediately change passwords for any DTU-related accounts. If the same credentials were reused on other services, those passwords must also be changed without delay.
*   **Vigilance Against Phishing:** Be extremely cautious of unexpected emails, text messages, or phone calls that appear to know your connection with DTU or possess personal information about you. Do not disclose passwords or sensitive information in response to such communications. Treat any sudden requests for authentication or login as suspicious.
*   **Monitoring for Identity Fraud:** Individuals concerned about the exposure of their Danish university data exposure CPR numbers should consider placing a credit alert on their CPR number to monitor for unauthorized financial activity. Regularly review bank statements and credit reports for any suspicious transactions.
*   **Information Sharing:** DTU is notifying potentially impacted individuals via e-Boks. However, the university urges the public to share this disclosure with any former employees, students, guests, or external partners who may not be directly reachable, emphasizing the wide scope of this breach.

**Related:** [ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign](/blog/shinyhunters-data-leaks-fuel-2000-sextortion-phishing-campaign), [SafePal Data Breach Exposes 39,798 Customer Order Details](/blog/safepal-data-breach-exposes-39798-customer-order-details)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/dtu-data-breach-exposes-200000-user-records-via-iam-compromise
