How the Breach Occurred
The Technical University of Denmark (DTU) has disclosed a serious security incident where unauthorized actors gained access to its identity and access management (IAM) system, known as DTUBasen. The attackers exploited compromised credentials to infiltrate the system, which has been in operation for over two decades. This unauthorized access allowed them to download a substantial volume of user data, the exact scope of which DTU is still working to determine.
What Data Was Exposed & Consumer Risks
The compromised DTUBasen system holds sensitive information for both current and former users. For active users, the exposed data may include Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, office locations, and employment details. Crucially, the dataset also contained the names, relationships, and telephone numbers of next of kin, where provided by active users. While data for former users is typically purged after six months, the breach could still impact individuals who were associated with DTU since 2003.
- Danish civil registration numbers (CPR)
- Full names and home addresses
- Profile pictures
- Work and personal contact details
- Employment-related information
- Next of kin details (names, relationships, phone numbers)
The primary risk to affected individuals is identity fraud. Cybercriminals can leverage exposed CPR numbers and other personal identifiers to impersonate victims, open fraudulent accounts, or conduct sophisticated phishing attacks that appear more legitimate due to the stolen personal information. The university itself has warned that this data can be used to make phishing attempts more convincing.
Protective Steps for Affected Consumers
DTU is notifying affected individuals primarily through its official e-Boks system. However, the university acknowledges that not all former students will be directly contacted, urging a broad dissemination of the warning. Anyone who has been a student, employee, guest, or external partner of DTU since 2003 should exercise extreme caution. Be vigilant against unsolicited communications via email, text, or phone that seem to have insider knowledge of your connection to DTU. Never disclose passwords or sensitive information in response to such requests. Treat any unexpected authentication prompts or login requests with suspicion. It is also strongly recommended to change passwords for any other online services that use the same credentials as your DTU account. Furthermore, consider placing a credit alert on your CPR number to monitor for fraudulent activity.
- Be wary of unsolicited communications referencing your DTU affiliation.
- Never share passwords or personal data in response to suspicious requests.
- Change passwords for any other accounts using the same credentials.
- Consider placing a credit alert on your civil registration number.
- Monitor financial accounts and credit reports for suspicious activity.