DTU (Denmark) IAM breach: DTUBasen access via compromised profiles — up to ~200k current/former users; CPR + next-of-kin risk
Technical University of Denmark (DTU) disclosed on 2 October 2026 a serious personal-data breach of DTUBasen, its identity and access management system. Attackers compromised DTU profiles and used them to access DTUBasen, downloading a large volume of personal data dating back to 2003. DTU cannot determine precisely what was taken or how many people were affected; DTUBasen holds ~40,000 active and ~160,000 former users (employees, students, guests, external partners). For active users, potentially exposed fields include Danish civil registration (CPR) numbers, full names, home addresses, profile pictures, work email/title/office details, and registered next-of-kin name/relationship/phone. Former-user home addresses, pictures, and next-of-kin are auto-deleted after six months, but CPR and names remain. Incident reported to the Danish Data Protection Agency and referred to authorities; IR contained with external specialists. Notifications via e-Boks for current/former employees and most students with CPR on file; public notice for guests/partners/next-of-kin DTU cannot reach directly. DTU warns of identity fraud and more convincing phishing. Primary: DTU English disclosure 2 Oct; wire: BleepingComputer 3 Oct.
- Product
- DTUBasen (DTU identity and access management)
- Versions
- n/a — institutional IAM/SaaS-style directory holding records since 2003
- Exploited in Australia?
- no
- Patch to
- AU operators with AU/EU students staffed against EU partners: treat foreign uni IAM breaches as identity-fraud feedstock (CPR-class IDs). Anyone with a DTU link since 2003: watch e-Boks; do not reuse DTU passwords; treat unexpected OTP/login prompts as hostile; consider CPR credit alert (Borger.dk). No AU org named.
Primary: DTU — Cyberattack on DTU: Notification of a personal data breach (2 Oct 2026) · Vendor: DTU (Danish) — Hackerangreb mod DTU: underretning om brud på persondatasikkerheden · BleepingComputer — Danish university DTU breach exposes data of up to 200,000 people (3 Oct 2026)
