Skip to content
Brief Security & Trust ·

Attackers downloaded data from DTU's login system; scope unclear

DTU says up to 200,000 current and former users may be affected, but it cannot say exactly what was taken.

In brief
  • Attackers used compromised DTU profiles to reach DTUBasen and downloaded a large amount of data. DTU cannot say exactly what was taken or whose.
  • The system keeps CPR numbers and full names for former users, while some other details are deleted after six months.

The Technical University of Denmark (DTU) said attackers got into DTUBasen and downloaded a large amount of data. DTUBasen is its identity and access management system, which records who may log in and what they can reach. DTU said the attackers compromised DTU profiles and used them to get in. The system holds about 40,000 active users and about 160,000 former ones, with data back to 2003. Up to 200,000 people may be affected.

DTU says it cannot determine exactly what was downloaded or how many people are affected. The sources do not say how the profiles were compromised. DTU said its IT team has contained the attack and that it told the Danish Data Protection Agency. The data may include CPR numbers (Danish national ID numbers) and full names. DTU will notify current and former employees, and almost all students whose CPR number it holds, through e-Boks, a Danish digital mailbox.

A system like this is a register of everyone who ever had access. DTU deletes former users' home addresses, photos and next-of-kin details after six months, but CPR numbers and full names stay. Leaders can ask how long they keep identity data on people who left, how far one ordinary profile can see, and whether bulk downloads raise alerts.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Technical University of Denmark (DTU).