The breach in the DTUBasen system, the identity management database of the Technical University of Denmark (DTU), may involve personal data corresponding to up to 200,000 current and former users. The university clarifies in its official statement that it does not know how many people were affected or what data was downloaded.

DTU reports that unknown individuals hacked into university user profiles and used them to gain access to the database. From there, they downloaded a large amount of information, the exact content of which has not yet been clarified, as confirmed by the BleepingComputer report.
See also: Mount Royal University: Data breach affects staff and students
What does the DTUBasen system contain?
DTU said the DTUBasen system contains information on about 40,000 active and 160,000 former users. These numbers reflect how many profiles are in the database, not how many have been confirmed to have been exposed. The breach in the DTUBasen system is still under investigation, so the university has not given a final number of victims.
Those potentially affected include employees, students, visitors and external partners. DTU clarifies that the database may contain information about those who have been associated with the institution since 2003, so former members of the university community should also monitor its official updates.
For active users, the personal data that may be included is CPR number, Danish personal registration number, full name, home address and profile photo, as well as work email address, position and office location. In some cases, the database also held names of relatives, their relationship to the user and contact numbers.

The DTU clarifies that for former users, CPR numbers and full names are retained, among other things, while addresses, photos and details of relatives are automatically deleted six months after leaving. This is personal data that may have been on the database, not information that the institution has confirmed was removed.
The use of CPR for identity verification makes the potential exposure particularly sensitive. The university warns that if the numbers and other information were leaked to third parties, it could be used for impersonation or more convincing phishing attempts. However, it has not been announced what data was included in the downloaded material.
See also: New data breach at Oxford University via CareerConnect
The investigation into the breach of the DTUBasen system
DTU said its IT incident response team had contained the attack and was working with external experts to determine its extent. The university reported the incident to the Danish Data Protection Authority. The Copenhagen Post, citing Ritzau, also reports that the National Special Crime Unit (NSK) is in contact with DTU about the case.
Employees, former employees and almost all current and former students for whom a CPR number is held are expected to receive a personal notification via e-Boks, the digital mailbox used in Denmark. The institution notes that it only has CPR numbers for a small number of visitors and external partners.

The public announcement is also addressed to those who cannot be notified directly. Anyone who has worked, studied, been hosted or collaborated with DTU since 2003 can check the updates and contact the university if they are concerned about their details.
How to protect potential users
DTU recommends increased caution in unexpected emails, text messages and phone calls, even when the sender knows real information about the recipient's relationship with the university. Users should not disclose passwords or other sensitive information, nor approve login requests that they did not initiate themselves.
Those who have used the same password at DTU and another service are asked to change it there as well. For potential risks of CPR number misuse, the announcement refers to the Borger.dk service to activate a credit check notification. These measures are precautionary and do not mean that use of the data has been confirmed.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In its official statement, DTU warns those with protected names or addresses to be particularly careful. If such information were to be disclosed to third parties, it could increase the risk of unwanted communication or tracking. The warning concerns a potential risk and does not confirm that a specific file was exposed.
See also: University of Hawaii: Cancer Center breach exposed important data
Until the investigation is complete, the key point is that the DTU has confirmed access to the system and the receipt of a significant amount of data, but not the exact scope of the exposure. The SecNews technical team points out that those who may be affected should rely on official notifications and treat any message requesting passwords or login actions with caution.
