The Technical University of Denmark (DTU) said attackers got into DTUBasen and downloaded a large amount of data. DTUBasen is its identity and access management system, which records who may log in and what they can reach. DTU said the attackers compromised DTU profiles and used them to get in. The system holds about 40,000 active users and about 160,000 former ones, with data back to 2003. Up to 200,000 people may be affected.
DTU says it cannot determine exactly what was downloaded or how many people are affected. The sources do not say how the profiles were compromised. DTU said its IT team has contained the attack and that it told the Danish Data Protection Agency. The data may include CPR numbers (Danish national ID numbers) and full names. DTU will notify current and former employees, and almost all students whose CPR number it holds, through e-Boks, a Danish digital mailbox.
A system like this is a register of everyone who ever had access. DTU deletes former users' home addresses, photos and next-of-kin details after six months, but CPR numbers and full names stay. Leaders can ask how long they keep identity data on people who left, how far one ordinary profile can see, and whether bulk downloads raise alerts.