Read as article
DTU Breach Exposes CPR Numbers of Up to 200,000 Users
By @sharedot · · 8 pages
- Cybersecurity
- Data Breach
- Identity Theft
- Denmark
Hackers used valid credentials to raid DTU's identity system, exposing CPR numbers, addresses and next-of-kin data for up to 200,000 people.
What happened at Denmark's largest technical university
The Technical University of Denmark disclosed on October 2, 2026 that attackers compromised legitimate user profiles and used them to enter DTUBasen, the identity and access management system covering roughly 40,000 active users and 160,000 former ones. According to Rescana's incident analysis, the exposed data may include Danish CPR numbers — the civil registration numbers equivalent to U.S. Social Security numbers — plus full names, home addresses, profile pictures, work emails, job titles, office locations and, for active users, next-of-kin details. DTU says it cannot determine exactly what was downloaded or how many people were affected, and the exposure window reaches back to records from 2003.
Why credential abuse is the surprising vector
There was no malware, ransomware or lateral movement here. Rescana maps the attack to MITRE ATT&CK technique T1078, Valid Accounts: adversaries logged in with real, compromised credentials and quietly exfiltrated a large volume of data from the IAM platform instead of disrupting systems. No threat actor has been attributed, and no indicators of compromise such as malware hashes or command-and-control infrastructure have been published at the time of writing.
The evidence and the timeline
The breach timeline is narrow: before October 2, attackers entered DTUBasen and extracted a large amount of data; on that day DTU publicly disclosed the incident, contained the attack via its IT incident response team, notified authorities, and began notifying affected individuals through e-Boks, Denmark's official digital mail service, as Rescana recounts. For former users, home addresses, profile pictures and next-of-kin details are deleted after six months, but CPR numbers and full names remain in the system — meaning even people who left DTU years ago are potentially exposed. The university has reported the breach to the Danish Data Protection Agency.
The stakes: identity data that never expires
That same dynamic is playing out in financial services: a class action filed by plaintiff Cari Fedorchak in Maryland federal court claims OneMain Financial exposed unencrypted names, addresses and Social Security numbers and failed to monitor its network or notify customers promptly, per Top Class Actions. The OneMain complaint argues exposed data could be used to open accounts, take out loans and file fraudulent tax returns — precisely the harms Danish regulators will weigh for DTU's affected users.
How breach response looks from here
DTU is working with external specialists to assess the full impact and providing public updates for people it cannot reach directly. Comparable U.S. incidents show what affected individuals can expect: per Claim Depot, TIAA — which disclosed its own September breach of names and Social Security numbers — is offering 24 months of Experian IdentityWorks credit monitoring, dark-web surveillance, identity restoration support and up to $1 million in identity theft insurance.
What comes next and what to do now
Investigation continues with no attribution of the attackers and no published IOCs, so organizations should validate any future indicators before acting on them, Rescana advises. Priorities for affected users: treat unexpected emails, texts and calls referencing DTU as suspicious, never share credentials in response to such contact, change passwords reused from DTU accounts, enable multi-factor authentication, and consider placing a credit alert on their CPR number via official Danish channels. For institutions, the case argues for credential audits, MFA everywhere, anomaly monitoring on IAM systems, and enforcing data-retention limits on sensitive fields like next-of-kin records.
Sources
- rescana.com › DTUBasen Data Breach at Technical University of Denmark (DTU) Exposes Sensitive Information of 200,000 Users
- cybersecuritynews.com › Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories
- topclassactions.com › OneMain Financial class action claims unencrypted PII exposed in data breach
- claimdepot.com › TIAA Discloses Data Breach Exposing Social Security Numbers