Stolen Credentials Open DTU Identity Platform to Large-Scale Data Download
Attacker used stolen credentials to breach DTU's DTUBasen identity system, potentially exposing data of 200,000 people including CPR numbers.
Illustrative image generated with AI
Attacker entered the university’s central identity system
The Technical University of Denmark (DTU) has disclosed a breach of DTUBasen, the identity and access management platform holding records for its university community. An attacker authenticated with compromised credentials and downloaded a large volume of data.
DTU has not been able to establish precisely which records or fields were taken. It also cannot confirm how many individuals were included in the download.
The university estimates that information linked to as many as 200,000 people may have been exposed. That number is a potential ceiling, not a confirmed victim count.
DTUBasen covers two broad populations: just under 40,000 people with active accounts and approximately 160,000 former users. According to DTU, the potentially affected population includes anyone connected to the institution as an employee, student, guest, or external partner since 2003.
The report describing DTU’s disclosure was published on October 3, 2026, at 10:35 AM. It says the university disclosed the incident on Friday, without providing that Friday’s calendar date. No date is given for the intrusion itself.
DTU described the incident as serious, although no formal severity score was reported.
The available account shows credential abuse, but not how access began
The known technical sequence is limited but consequential. The attacker possessed valid compromised credentials, used them to enter DTUBasen, and then extracted substantial amounts of information.
The reporting does not explain how the credentials were compromised, which account they belonged to, or what level of access they provided. It also does not identify whether the attacker escalated privileges, maintained persistence, or accessed systems beyond DTUBasen.
Valid-account access can make the boundaries of a breach difficult to reconstruct because malicious activity may initially resemble legitimate use. In this case, DTU has confirmed the large download but has not resolved its precise contents.
That uncertainty is central to interpreting the 200,000 figure. The number describes the possible reach of the incident based on the population represented in DTUBasen. It does not demonstrate that the attacker copied every user record, nor that every available field was taken for each person.
Likewise, membership in one of the identified groups indicates possible exposure rather than confirmed inclusion in the extracted dataset.
CPR numbers and detailed personal records may have been exposed
For current users, the information potentially involved includes Danish civil registration numbers, commonly known as CPR numbers. Other possible data categories are:
- Full names and home addresses
- Profile photographs
- Work email addresses
- Job titles and office locations
- Other employment-related information
- Names, relationships, and telephone numbers for next of kin, when supplied by an active user
Those categories should not be interpreted as applying uniformly to every person. DTU said it holds CPR numbers for only a small subset of guests and external partners. It also said that DTUBasen does not contain CPR numbers for the next of kin listed as contacts.
Some fields are subject to different retention rules after a person leaves the university. Home addresses, profile photographs, and next-of-kin information are automatically removed six months after a user becomes a former user.
That policy does not establish that those details were absent from every former-user record implicated in the breach. The reported information does not show which records were downloaded or whether particular former users were still within that six-month retention window.
The combination of identifiers, contact details, workplace information, and university affiliations creates several possible avenues for abuse. DTU specifically warned that CPR numbers and associated personal data could be used for identity fraud. The contextual information could also make phishing attempts more persuasive.
University-specific details could lend credibility to scams
Potentially affected people should be alert to unexpected emails, text messages, telephone calls, authentication prompts, and login activity. DTU emphasized communications in which the sender appears to know about the recipient’s relationship with the university or possesses personal details.
A reference to a DTU role, job title, office, address, or previous university connection should not be treated as proof that a message is genuine. Such information could be used to construct an impersonation attempt that appears tailored to its target.
DTU advised people not to provide passwords or sensitive information when responding to unsolicited communications. Unexpected authentication requests and unexplained login events should also be treated as suspicious.
Anyone who reused DTU credentials on another service should change the password for that service. The guidance applies specifically where the same credentials were used in multiple places; changing only the DTU password would not invalidate a reused password on an unrelated platform.
The university also recommended placing a credit alert on an affected CPR number. This measure is relevant to people whose civil registration number may have formed part of the downloaded information.
DTU’s warnings describe potential misuse rather than confirmed downstream fraud. The reported account does not identify individuals known to have suffered identity theft or successful phishing as a result of the breach.
E-Boks notices will not reach the entire potential population
DTU plans to send notifications through e-Boks, the official mailbox system it uses to distribute notices and documents to students and employees.
The direct-notification process differs by user category. The university said it would notify every current and former employee. However, it will not directly notify every current or former student whose CPR number it holds.
DTU therefore issued a public disclosure to reach people it cannot contact individually. It also asked that the information be shared with former employees, students, guests, and external partners.
Consequently, the absence of an e-Boks message does not by itself mean that a person is outside the potentially affected group. DTU’s broader warning covers qualifying university relationships dating back to 2003.
The reverse distinction also matters. Receiving a warning, or belonging to one of the named groups, does not confirm that the attacker downloaded a particular person’s record or every listed category of data. DTU has not determined exposure at that level.
The immediate response is vigilance and removal of reused passwords
For potentially affected people, the practical steps reported by DTU are:
- Scrutinize unsolicited emails, messages, and calls, especially when they mention a DTU connection or personal information.
- Do not send passwords or sensitive data in response to unexpected contact.
- Treat unrequested authentication prompts and unfamiliar login activity as suspicious.
- Replace passwords on other services if they match the credentials used for the DTU account.
- Place a credit alert on a CPR number that may have been affected.
The published account does not describe technical remediation within DTUBasen or provide indicators of compromise for security teams to search. That limitation applies to the information contained in the cited report; it should not be read as a claim that DTU has released no additional material elsewhere.
The central unresolved question is the exact scope of the extraction. DTU has identified the compromised platform, the use of stolen credentials, and the broad categories of people and data potentially involved. It has not established which individual records were actually downloaded.
For that reason, “up to 200,000” remains an estimate of possible exposure. The confirmed event is narrower: an attacker used compromised credentials to access DTUBasen and removed a large amount of data from an identity system spanning active and former members of the DTU community.
Sources
This article is an original reworking based on the sources below.




