The Technical University of Denmark (DTU) has confirmed a serious personal data breach. Attackers used compromised DTU user profiles to get into DTUBasen, the university's identity and access management (IAM) system, and downloaded what DTU calls "a large amount of data." DTU disclosed the breach on Friday, 2 October 2026, in an official notice published in Danish and English. The university says DTUBasen holds records on about 40,000 active users and about 160,000 former users, with personal data going back to 2003. That is why almost every outlet reports that up to 200,000 people may be affected. DTU stresses that it cannot say exactly what data was taken or how many people are affected. No threat actor has been named, and nobody has publicly claimed the attack.
What Happened
DTU's notice, reproduced by DR, TV 2 Kosmopol, NordiskPost, The Local and Mirage News, says this was a "targeted hacker attack" on DTUBasen. The university's IT incident response team says it has contained the intrusion and is investigating with outside specialists. DTU has reported the breach to the Danish Data Protection Agency (Datatilsynet) and handed the case to "the relevant authorities." The Ritzau wire story carried by DKNyt adds that Denmark's National Unit for Special Crime (NSK) is in contact with DTU about the case. Only that one source reports the NSK involvement, and DTU's own statement does not name the agency.
University Director Bjarke Bak Christensen called it "a serious attack on DTU." He said the university's priorities are working out the scope, limiting the consequences and making sure affected people are told what to do. DTU has promised more updates as its investigation and the authorities' inquiry continue.
On the numbers: DTU's own wording is "up to 200,000," which is the sum of about 40,000 active and 160,000 former users. BleepingComputer, DR, TV 2 Kosmopol, NordiskPost and The Local all use the same figure. One sentence in the Ritzau/DKNyt piece says "over 200,000," but the same article also says "200,000 may be affected." The "over" looks like a wording slip and is not backed by DTU. Readers should treat 200,000 as a ceiling based on how many records the system holds. It is not a confirmed count of people whose data was taken.
What Was Taken
DTU says it cannot determine exactly what was downloaded. These are the categories its notice and the press coverage list as stored in DTUBasen:
For active users (about 40,000): - CPR number (Danish civil registration number), full name, home address and profile photo - Work email address, job title, office location and other employment details - Next-of-kin details: name, relationship and phone number (BleepingComputer, TV 2 Kosmopol and DTU's notice as carried by Mirage News)
For former users (about 160,000): BleepingComputer and the DTU notice give former users a separate category list. The source excerpts available for this brief are cut off before that list, so we can't list those fields here. The Local reports that CPR numbers and full names could be affected for former users, and that addresses, photos and phone numbers relate mainly to active users.
The people potentially affected include current and former staff, students, guests and external partners dating back to 2003. The CPR number matters most. In Denmark it is a lifelong national identifier that is hard to change and is used for banking, healthcare and government services. TV 2 Kosmopol reports that DTU has specifically warned people with name and address protection to take extra care.
Why It Matters
IAM systems are high-value targets. DTUBasen isn't a side database. It is the identity backbone that decides who can access what. One compromise exposed more than two decades of records on staff, students, guests and partners, plus next-of-kin details about people who never had any relationship with DTU.
Long retention made the damage bigger. About 80% of the potentially affected records belong to former users. Data kept since 2003 turned a breach of current users into a breach of a whole generation of alumni and ex-staff.
This data is built for social engineering. DTU itself warns that the data "could make phishing attempts or other misuse appear more believable" (The Local). Names, job titles, office locations, work emails and next-of-kin contacts are enough for convincing pretexting, impersonation and MFA-fatigue attacks against DTU and its research partners.
Universities are a sector under pressure. Ritzau/DKNyt cites a 2025 assessment by Denmark's Agency for Civil Protection (Styrelsen for Samfundssikkerhed) that rates the cybercrime threat to Danish universities as "very high." It also quotes Aarhus University cybersecurity professor Jens Myrup Pedersen, who says universities hold very large amounts of personal data and often run older systems that may not meet 2026 security standards. He was careful to say he couldn't comment on DTU's security specifically.
The Attack Technique
What is confirmed is limited. DTU says attackers "compromised DTU profiles" and used them to get into DTUBasen. BleepingComputer describes this as using compromised credentials. The Ritzau report says several profiles were compromised. DTU has not said:
- How the accounts were compromised (phishing, credential stuffing, infostealer malware, password reuse or MFA bypass)
- Whether the accounts had privileged or administrative access to DTUBasen
- How long the attackers had access before they were detected
- Whether ransomware, extortion or a data-leak site is involved
DTU's own advice to users points to credential-based threats. It tells them to reject unexpected login or approval prompts and to change passwords on any service where they reused their DTU password (TV 2 Kosmopol). That hints at concern about MFA push abuse and credential reuse, but DTU has not confirmed that either was the initial access route.
Professor Myrup Pedersen raised two questions any defender should ask after an incident like this: which accounts had access to all of this personal data, and was there a limit on how much data could be pulled before an alert went off? DTU says a "large amount" of data was downloaded, which suggests bulk extraction from the IAM store wasn't stopped in time.
What Organizations Should Do
- Treat IAM and directory systems as Tier 0. Limit read access to identity stores to a small set of dedicated, phishing-resistant-MFA-protected admin accounts. Remove any standing bulk-query rights from ordinary user or service accounts.
- Alert on bulk exports. Set volume and rate limits, plus anomaly detection, on queries and exports from IAM databases. A normal account pulling tens of thousands of records should trigger an alert or block within minutes, not be found afterwards.
- Use phishing-resistant MFA and stop push fatigue. Move away from simple push approvals to FIDO2/passkeys or number matching, especially for staff with access to identity or HR systems. Watch for repeated MFA prompts on the same account.
- Enforce data minimisation and retention limits. Purge or archive former-user records, especially national ID numbers and next-of-kin data, once there is no lawful need to keep them. GDPR's storage-limitation principle applies, and every year of retention adds to the exposure.
- Monitor for compromised credentials. Check infostealer logs and breach corpora against your user base. Force resets for exposed accounts, and block password reuse with known-breached password checks.
- Prepare for follow-on phishing. Universities and research partners connected to DTU should warn their users about DTU-themed phishing, fake IT-support calls and pretexting that uses accurate job and contact details. Users should also consider DTU's advice to place a credit alert on their CPR number via Borger.dk.
Sources: Danish university DTU breach exposes data of up to 200,000 people | Hackerangreb mod DTU: Underretning om brud på persondatasikkerheden | DTU har været udsat for et hackerangreb Indland DR | DTU udsat for kæmpe hackerangreb: "Det her er alvorligt" TV 2 Kosm... | A Danish university has been hit by a cyberattack - NordiskPost | Hacker attack at DTU could affect up to 200,000 people | DTU Reports Personal Data Breach After Cyberattack Mirage News | Professor: Gamle it-systemer gør universiteter til hackingmål