Skip to content
Security & Trust

DTU's login system kept records back to 2003, and hackers downloaded data

The Danish university cannot say what was taken or whose. Up to 200,000 people may be affected.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
DTU's login system kept records back to 2003, and hackers downloaded data

AI-generated image for WebPulse. About our images

In brief
  • Hackers accessed the identity system of the Technical University of Denmark (DTU) and downloaded a large amount of data. Up to 200,000 current and former users may be affected.
  • DTU says it cannot determine what was downloaded or how many people are affected. Records go back to 2003, and former users' CPR numbers and names remain stored.
  • Leaders should ask what their identity system stores, how long, and whether logs could show exactly what an intruder downloaded.

An identity system answers one question: who is this person? Over time it also becomes a record of everyone who has ever been in the organisation. The breach at the Technical University of Denmark (DTU) shows what that record can turn into if no one prunes it.

What DTU reports

DTU says unauthorised people gained access to DTUBasen, its identity and access management system, in a targeted cyberattack. They downloaded a large amount of data. DTU says its own IT incident response team has contained the attack. It is now investigating how far it went, alongside outside specialists.

The notice is candid about what is unknown. DTU says it cannot determine precisely what was downloaded or how many people are affected. It has reported the incident to the Danish Data Protection Agency.

Up to 200,000
People who may be affected
Source: DTU breach notice, reported by BleepingComputer on October 3, 2026

How the attack worked, as far as is known

An identity and access management system decides who can log in and to what. It often holds profile details too. That makes it a single place where many kinds of personal data meet.

DTU says the intruders compromised DTU profiles and used them to reach DTUBasen. BleepingComputer, which covered the notice, describes this as the attacker using compromised credentials to log in. The notice does not say how the profiles were compromised.

The point for leaders is the entry route. DTU says they got in by compromising DTU profiles and using them to reach DTUBasen. Once inside, they downloaded data.

The record that outlived the relationship

DTUBasen holds data on about 40,000 active users and about 160,000 former users. The attackers gained access to personal data going back to 2003, DTU says.

About 160,000
Former users stored in DTUBasen
Source: DTU breach notice, reported by BleepingComputer on October 3, 2026

DTU does clear out some data. Six months after a user leaves, the system automatically deletes their home address, profile picture and next-of-kin details. But it still holds their CPR numbers and full names. A CPR number is the Danish civil registration number.

This illustrates a gap that can arise. A retention rule can clean up the fields that look sensitive and still leave the identifiers that matter most. DTU warns that CPR numbers could be used for identity fraud and to make phishing more convincing.

A password can be reset. A person cannot easily replace a national ID number. That is why an old directory entry can cost its owner more than it ever cost the institution to keep.

2003
Personal data reaches back to
Source: DTU breach notice, reported by BleepingComputer on October 3, 2026

The people DTU cannot reach

DTU will notify current and former employees, and almost all current and former students with CPR numbers on file, through e-Boks. That is the Danish official mailbox system. Guests and external partners are harder: DTU holds CPR numbers for only a small number of them.

Next of kin are the hardest group. Active users could register a relative's name, relationship and phone number. DTU holds no CPR numbers for those relatives, so it cannot contact them directly. It has issued a public notice and asks readers to pass it on.

These people never joined the university. Someone else listed them, and they now sit in a database that was breached. That is a human cost no one planned for.

Questions to put to your team

First: which systems hold identity records, and which personal identifiers sit in them? Second: when someone leaves, what is deleted, and what stays? Check the identifiers, not only the obvious fields.

Third: if an intruder used a valid account, could your logs show exactly which records they downloaded? DTU's inability to say what was taken is the scenario to test against.

Fourth: how would you reach people for whom you hold no contact details? Fifth: how many accounts can reach the identity directory, and what checks stop a stolen login from using it?

An identity system is built to remember who someone is. The lesson here is to decide, on purpose, how much of that memory you can afford to lose.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Technical University of Denmark (DTU).

Share this insight