Danish university DTU breach exposes data of up to 200,000 people
TLDR
- The Technical University of Denmark (DTU) says hackers used compromised credentials to access DTUBasen, its identity and access management system, and downloaded a large amount of data covering more than two decades of users.
- Up to 200,000 current and former users may be affected: around 40,000 active users and 160,000 former users, including employees, students, guests and external partners since 2003.
- Exposed data may include Danish civil registration (CPR) numbers, full names, home addresses, profile pictures, employment details, and the names and phone numbers of users' next of kin.
- DTU cannot yet determine exactly what was taken or how many people are affected, has reported the breach to Denmark's data protection agency, Datatilsynet, and is notifying people through the e-Boks digital mail service, though not all affected students will be contacted directly.
DTU disclosed on 2 October that an attacker logged into DTUBasen using compromised credentials, gaining access to more than two decades of user data.1 The university said it "cannot determine precisely what information was downloaded or how many people have been affected," but DTUBasen stores records for close to 40,000 active users and around 160,000 former users.1 Potentially exposed information for active users includes CPR numbers, full names, home addresses, profile pictures, work email addresses, job titles and office locations, along with the names, relationships and phone numbers of next of kin where provided.1 For former users, home address, profile picture and next-of-kin details are automatically deleted after six months, limiting what could have been taken for that group.2
University director Bjarke Bak Christensen called it "a serious attack on DTU" and said the immediate priority was establishing the scope, limiting consequences and ensuring affected people are notified.1 DTU contained the attack on the morning of 2 October and reported it to Datatilsynet, the Danish data protection agency, as well as other relevant authorities.2 The university has not identified who was responsible.2 Anyone who has been a DTU employee, student, guest or external partner since 2003 may be affected; current and former employees will be notified directly through e-Boks, but not all current and former students will be, so DTU is asking people to share the public disclosure with others who may be affected.1
DTU warned that exposed CPR numbers and personal details could be used for identity fraud or to make phishing attempts more convincing, and urged people to treat unexpected logins, authentication requests or messages referencing their DTU connection as suspicious, and to change passwords reused across other services.1
Why it matters: a single compromised-credential login into an identity-management system handing over more than two decades of a university's personal records, including a national ID number used across Danish public and financial services, shows how one weak point in access control can expose far more than the system it was built to protect.
Sources
- Danish university DTU breach exposes data of up to 200,000 people (BleepingComputer)
- DTU data breach may affect personal information of 200,000 current and former users (The Copenhagen Post)