2 Remove Virus

DTU cyberattack puts personal data of up to 200,000 people at risk

The Technical University of Denmark (DTU) has suffered a major data breach that could affect up to 200,000 current and former students, employees, and other people connected to the university.

 

 

Attackers gained unauthorized access to DTUBasen, DTU’s system for managing user identities and access rights. The university confirmed that a large amount of data was downloaded before the intrusion was contained.

DTUBasen contains information dating back to 2003 and covers approximately 40,000 active users and 160,000 former users. However, DTU has stressed that these figures represent the number of people whose information may have been exposed, not a confirmed number of victims.

The university has not yet determined exactly which records were downloaded. Information stored in the system can include names, Danish CPR numbers, home addresses, profile pictures, work email addresses, job titles and office information.

Some active users may also have stored emergency contact details, including the name, relationship and phone number of their next of kin. DTU retains less information about former users because some data, including home addresses and profile pictures, is automatically deleted six months after they leave.

According to DTU, the attackers compromised several university user accounts and used them to access DTUBasen. The university has not disclosed how those accounts were initially compromised or identified who was responsible.

DTU’s incident response team contained the attack and brought in external cybersecurity specialists to investigate. The breach has also been reported to the Danish Data Protection Agency and other relevant authorities.

People whose information was exposed could face an increased risk of phishing and identity fraud. Personal details obtained from the university could help criminals create convincing emails, messages or calls that appear to come from DTU or another trusted organization.

DTU is contacting current and former employees and most current and former students whose CPR numbers are stored in the system through Denmark’s e-Boks digital mail service. The university has also issued a wider public warning because it cannot directly contact every potentially affected guest, external partner, or emergency contact.

The investigation is continuing, and DTU still does not know exactly how many people had their information downloaded or the full amount of data taken during the attack.