The Technical University of Denmark says a DTU data breach may affect approximately 200,000 current and former users after attackers accessed the university’s identity and access management system and downloaded a large amount of data. DTU has contained the attack, but it cannot determine exactly which information was taken or how many people were affected.
What happened in the DTU data breach
DTU disclosed on October 2, 2026, that unauthorized people compromised DTU profiles and used them to access DTUBasen, the university’s identity and access management system. The system contains personal data dating back to 2003.
The university said its incident response team contained the attack and is investigating with external specialists. DTU reported the incident to the Danish Data Protection Agency and referred it to the relevant authorities.
What is confirmed
DTU confirmed that attackers gained unauthorized access to DTUBasen and downloaded a large amount of data. The system contains records for approximately 40,000 active users and 160,000 former users.
People potentially affected include current and former employees, students, guests, and external partners. Information stored for active users may include Danish civil registration numbers, full names, home addresses, profile photographs, work email addresses, job titles, office locations, and other employment information.
The system may also contain the names, relationships, and telephone numbers of next of kin when users provided that information. DTU says home addresses, profile photographs, and next-of-kin information for former users are automatically deleted after six months, but CPR numbers and full names may remain.
What remains unknown
DTU says it cannot determine precisely what information the attackers downloaded or how many people were affected. The university has not publicly identified the attackers, disclosed when the intrusion began, or said whether the stolen information has been published or used for fraud.
The figure of 200,000 represents the approximate number of active and former users whose information is stored in DTUBasen. It should not be treated as a confirmed count of individual victims.
Why the breach matters
Identity systems are high-value targets because they can combine authentication information with detailed personal records. DTU warns that exposed CPR numbers and other personal data could be used for identity fraud or to make phishing attempts more convincing.
Attackers may impersonate university staff, government services, banks, employers, or account-support teams. Messages may reference a person’s DTU connection or other accurate details to pressure the recipient into revealing passwords, approving a login request, opening a malicious attachment, or sending money.
Who should take precautions
Anyone who has been a DTU employee, student, guest, or external partner since 2003 may be affected. People listed as next of kin in DTUBasen may also have contact details involved.
DTU says current and former employees, along with almost all current and former students for whom it holds a CPR number, will receive notices through e-Boks. The university issued a public notice because it cannot directly contact every guest, external partner, former student, or next of kin who may be affected.
Practical defensive actions
Verify messages through trusted channels
Be cautious with unexpected emails, text messages, calls, and authentication prompts, especially when the sender knows personal details or mentions DTU. Verify requests through a known DTU contact method or by navigating directly to an official website.
Protect passwords and accounts
Do not share passwords, one-time codes, or confidential information in response to an unexpected request. Change passwords on any service where a DTU password was reused and enable multifactor authentication wherever possible. Never approve a login prompt that you did not initiate.
Monitor for identity fraud
Affected people should follow DTU’s instructions and consider the identity-protection options available in Denmark, including placing a credit alert against a CPR number through Borger.dk. Review bank, payment, tax, and government accounts for unfamiliar activity.
Strengthen identity-system security
Organizations should treat identity and access management platforms as critical infrastructure. Require phishing-resistant multifactor authentication for privileged access, review dormant accounts, monitor unusual downloads and bulk directory queries, restrict access by role, and alert on sign-ins from unexpected devices or locations.
Sources
Technical University of Denmark: Cyberattack on DTU and notification of a personal data breach
BleepingComputer: DTU breach exposes data of up to 200,000 people