- Hackers accessed the identity system of the Technical University of Denmark (DTU) and downloaded a large amount of data. Up to 200,000 current and former users may be affected.
- DTU says it cannot determine what was downloaded or how many people are affected. Records go back to 2003, and former users' CPR numbers and names remain stored.
- Leaders should ask what their identity system stores, how long, and whether logs could show exactly what an intruder downloaded.
An identity system answers one question: who is this person? Over time it also becomes a record of everyone who has ever been in the organisation. The breach at the Technical University of Denmark (DTU) shows what that record can turn into if no one prunes it.
What DTU reports
DTU says unauthorised people gained access to DTUBasen, its identity and access management system, in a targeted cyberattack. They downloaded a large amount of data. DTU says its own IT incident response team has contained the attack. It is now investigating how far it went, alongside outside specialists.
The notice is candid about what is unknown. DTU says it cannot determine precisely what was downloaded or how many people are affected. It has reported the incident to the Danish Data Protection Agency.
How the attack worked, as far as is known
An identity and access management system decides who can log in and to what. It often holds profile details too. That makes it a single place where many kinds of personal data meet.
DTU says the intruders compromised DTU profiles and used them to reach DTUBasen. BleepingComputer, which covered the notice, describes this as the attacker using compromised credentials to log in. The notice does not say how the profiles were compromised.
The point for leaders is the entry route. DTU says they got in by compromising DTU profiles and using them to reach DTUBasen. Once inside, they downloaded data.
The record that outlived the relationship
DTUBasen holds data on about 40,000 active users and about 160,000 former users. The attackers gained access to personal data going back to 2003, DTU says.
DTU does clear out some data. Six months after a user leaves, the system automatically deletes their home address, profile picture and next-of-kin details. But it still holds their CPR numbers and full names. A CPR number is the Danish civil registration number.
This illustrates a gap that can arise. A retention rule can clean up the fields that look sensitive and still leave the identifiers that matter most. DTU warns that CPR numbers could be used for identity fraud and to make phishing more convincing.
A password can be reset. A person cannot easily replace a national ID number. That is why an old directory entry can cost its owner more than it ever cost the institution to keep.
The people DTU cannot reach
DTU will notify current and former employees, and almost all current and former students with CPR numbers on file, through e-Boks. That is the Danish official mailbox system. Guests and external partners are harder: DTU holds CPR numbers for only a small number of them.
Next of kin are the hardest group. Active users could register a relative's name, relationship and phone number. DTU holds no CPR numbers for those relatives, so it cannot contact them directly. It has issued a public notice and asks readers to pass it on.
These people never joined the university. Someone else listed them, and they now sit in a database that was breached. That is a human cost no one planned for.
Questions to put to your team
First: which systems hold identity records, and which personal identifiers sit in them? Second: when someone leaves, what is deleted, and what stays? Check the identifiers, not only the obvious fields.
Third: if an intruder used a valid account, could your logs show exactly which records they downloaded? DTU's inability to say what was taken is the scenario to test against.
Fourth: how would you reach people for whom you hold no contact details? Fifth: how many accounts can reach the identity directory, and what checks stop a stolen login from using it?
An identity system is built to remember who someone is. The lesson here is to decide, on purpose, how much of that memory you can afford to lose.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Technical University of Denmark (DTU).





