The Technical University of Denmark (DTU) disclosed a personal-data breach after attackers used compromised user credentials to access DTUBasen, its identity and access management system, and download data. Up to approximately 200,000 current and former users may be affected, with records dating back to 2003. Potentially exposed information includes Danish civil registration (CPR) numbers, names, addresses, contact details, employment information, profile photographs, and registered next-of-kin details. DTU cannot determine precisely which records were downloaded or how many people were affected.
DTU said it contained the attack, engaged external specialists, notified the Danish Data Protection Authority, and referred the incident to relevant authorities for investigation. The university is notifying affected individuals where possible and using its public disclosure to reach people it cannot contact directly. It warned of identity theft and targeted phishing risks, advising affected users to practice password hygiene, remain alert to unsolicited communications, and consider placing a credit warning against their CPR number where appropriate.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
DTU issued a public notice warning that data belonging to approximately 40,000 active and 160,000 former users, including CPR numbers and personal details, may have been exposed. The university warned of identity fraud and targeted phishing risks and used the disclosure to reach people it could not contact directly.
DTU notified Datatilsynet, the Danish Data Protection Authority, of the personal-data breach. It also referred the matter to relevant authorities for further investigation.
DTU began investigating the incident with external specialists to establish the extent of the attack and its consequences.
DTU's IT incident-response team contained the attack against DTUBasen.
Attackers used compromised DTU user accounts to gain unauthorized access to DTUBasen, the university's identity and access management system, and download a large quantity of data. DTU could not determine precisely which information was taken or how many people were affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourceteiss.co.uk
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourcecert.dk
Open sourcecomputerworld.dk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.