DTU Data Breach Exposes 200,000 Affected in Cybersecurity Alert

www.news4hackers.com-dtu-data-breach-exposes-200-000-affected-in-cybersecurity-alert-dtu-data-breach-exposes-200-000-affected-in-cybersecurity-alert

The Technical University of Denmark (DTU) has confirmed that information for up to 200,000 individuals may have been compromised following an unauthorized intrusion into its identity and access management system.

Breach Details

The breach involved the exploitation of stolen credentials to access DTUBasen, the university’s identity and access management (IAM) platform, which contains records spanning more than 20 years. DTU stated that while the exact scope of the data exposure remains under investigation, the system holds details for approximately 40,000 active users and 160,000 former users.

Data Exposed

The compromised dataset includes personal information such as Danish civil registration numbers (CPR), full names, residential addresses, and profile photographs for current users. Additional employment-related data, including work addresses, job titles, and office locations, was also accessible. For active users, records of next of kin—such as names, relationships, and contact numbers—were included if provided. Former users’ data is subject to automatic deletion after six months, including residential addresses, profile pictures, and next of kin information.

University Response

University leadership emphasized the severity of the incident, with Director Bjarke Bak Christensen expressing regret over the uncertainty caused to affected individuals. He noted that the institution’s priority has been to assess the breach’s impact, mitigate consequences, and inform those affected about necessary precautions.

Notification Process

The university warned that exposed CPR numbers and personal details could be exploited for identity fraud or to enhance phishing campaigns. Not all affected individuals will receive direct notifications via e-Boks, the official digital mailbox system used by DTU. Current and former employees will be notified, but the university clarified that not all students with CPR numbers stored in its systems will receive direct communication.

Advice to Affected Individuals

DTU highlighted that CPR numbers are retained only for a limited number of guests and external partners, and next of kin contact details are not stored for individuals not directly affiliated with the institution. To reach those unable to contact directly, the university has issued a public disclosure urging affected individuals, including former employees, students, guests, and partners, to share the information widely. Individuals who were affiliated with DTU since 2003 are advised to remain vigilant against unsolicited communications that reference their connection to the university or personal data.

Conclusion

The institution emphasized that sensitive information should never be disclosed through unexpected messages or login requests. The breach underscores the risks of credential compromise and the importance of proactive security measures. DTU has not disclosed the specific attack vector or threat actor responsible for the incident.


Blog Image

About Author

en_USEnglish