Executive Summary
The Technical University of Denmark (DTU) experienced a significant data breach in early October 2026, exposing personal information of up to 200,000 current and former users. Attackers gained unauthorized access to DTUBasen, DTU’s identity and access management (IAM) system, by compromising legitimate user credentials. The breach potentially affects employees, students, guests, and external partners, with data exposure dating back to 2003. Exposed information may include Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, office locations, and next-of-kin details. The incident has been reported to the Danish Data Protection Agency and relevant authorities. DTU’s IT incident response team has contained the attack and is working with external specialists to assess the full impact. There is an increased risk of identity theft and targeted phishing as a result of this breach. No specific threat actor has been attributed, and no malware or technical indicators have been published at the time of writing. All information in this summary is based on official DTU disclosures and corroborated by independent media reports (DTU official statement, BleepingComputer, The Copenhagen Post).
Technical Information
The breach at DTU was executed through the compromise of user credentials, granting attackers access to the university’s DTUBasen IAM system. This system manages identity and access for approximately 40,000 active users and 160,000 former users, including employees, students, guests, and external partners. The attack vector aligns with the MITRE ATT&CK technique T1078: Valid Accounts, where adversaries use legitimate credentials to gain unauthorized access (MITRE ATT&CK T1078).
Once inside DTUBasen, the attackers were able to access and exfiltrate a large volume of data. The compromised data includes highly sensitive personal information such as Danish CPR numbers (equivalent to Social Security Numbers), full names, home addresses, profile pictures, work email addresses, job titles, office locations, and, for active users, next-of-kin details (name, relationship, and telephone number). For former users, home addresses, profile pictures, and next-of-kin information are deleted after six months, but CPR numbers and full names remain in the system.
The attack was detected and contained by DTU’s IT incident response team, who worked with external specialists to investigate the breach. The university has publicly acknowledged that it cannot determine precisely what information was downloaded or the exact number of affected individuals. The breach has been reported to the Danish Data Protection Agency (Datatilsynet) and other relevant authorities for further investigation.
No evidence of malware deployment, privilege escalation, or lateral movement beyond the initial credential compromise has been reported. The attack appears to have been focused on data exfiltration rather than system disruption or ransomware deployment. The specific method of data exfiltration has not been detailed, but the MITRE ATT&CK technique T1041: Exfiltration Over C2 Channel is applicable for general data exfiltration activities (MITRE ATT&CK T1041).
No threat actor or group has been publicly attributed to this incident. The use of compromised credentials to target IAM systems is a common tactic among both financially motivated cybercriminals and state-sponsored actors. The higher education sector is frequently targeted due to the large volume of sensitive personal data and often less mature IAM security controls.
The breach highlights the critical importance of robust IAM security, including strong password policies, multi-factor authentication, regular credential audits, and monitoring for suspicious access patterns. The exposure of CPR numbers and other personal data significantly increases the risk of identity theft, social engineering, and targeted phishing attacks against affected individuals.
Affected Versions & Timeline
The affected system is DTUBasen, DTU’s identity and access management platform, which contains data on users dating back to 2003. The breach impacts both current and former users, including employees, students, guests, and external partners.
The incident timeline is as follows: Prior to 2 October 2026, attackers compromised DTU user profiles and gained access to DTUBasen, extracting a large amount of data. On 2 October 2026, DTU publicly disclosed the breach, notified authorities, and began notifying affected individuals via e-Boks, Denmark’s official digital mail service. The attack was contained by DTU’s IT incident response team on the same day. On 3 October 2026, additional details and sector analysis were published by independent media outlets.
DTU has stated that it is not possible to determine precisely what information was downloaded or how many people have been affected. The university continues to investigate the incident with external specialists and is providing updates as new information becomes available.
Threat Activity
The threat activity in this incident centers on the use of compromised credentials to access and exfiltrate data from DTUBasen. The attack method is consistent with MITRE ATT&CK technique T1078: Valid Accounts, where adversaries leverage legitimate user credentials to bypass access controls. There is no evidence of malware deployment, privilege escalation, or lateral movement beyond the initial access.
The attackers targeted a high-value academic institution with a large and diverse user base. The data types accessed—CPR numbers, names, addresses, and next-of-kin information—are highly valuable for identity theft, financial fraud, and social engineering. The breach has not been attributed to any specific threat actor or group, and no technical indicators (such as malware hashes or command-and-control infrastructure) have been published.
Credential-based attacks on IAM systems are a growing threat in the higher education sector, with similar incidents reported at other universities worldwide. The open and collaborative nature of academic environments, combined with the long-term retention of sensitive personal data, makes universities attractive targets for cybercriminals and state-sponsored actors alike.
Mitigation & Workarounds
The following mitigation steps are recommended, prioritized by severity:
Critical: All users who have been associated with DTU since 2003 should remain vigilant for suspicious emails, text messages, and phone calls, especially those referencing their connection to DTU or containing personal information. Users should not disclose passwords or sensitive information in response to unexpected communications and should treat sudden authentication requests or logins as suspicious.
High: Users are advised to change passwords for any services where the same credentials as their DTU account have been used. Multi-factor authentication should be enabled wherever possible to reduce the risk of credential compromise.
High: Individuals whose CPR numbers may have been exposed should consider placing a credit alert or fraud watch on their identification number through official Danish channels (e.g., Borger.dk).
Medium: DTU and similar institutions should conduct a comprehensive review of IAM security controls, including password policies, credential management, and monitoring for anomalous access patterns. Regular audits and penetration testing of IAM systems are recommended.
Medium: Institutions should ensure that data retention policies are enforced, and that sensitive information (such as next-of-kin details) is deleted promptly when no longer required.
Low: Users with name and address protection should be particularly vigilant for unwanted contact or harassment and report any suspicious activity to authorities.
DTU has already notified affected individuals via e-Boks where possible and is providing public updates to reach those it cannot contact directly. The university continues to work with external specialists and authorities to investigate the breach and implement additional security measures.
Indicators of Compromise
At the time of writing, no public indicators of compromise (IOCs) have been released by DTU or independent researchers. Organizations should monitor for updates from DTU and relevant authorities and validate any future indicators before enforcement.
References
Official DTU statement: https://www.dtu.dk/english/newsarchive/2026/10/cyberattack-on-dtu_notification-of-a-personal-data-breach
BleepingComputer: https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/
The Copenhagen Post: https://cphpost.dk/2026-10-02/life-in-denmark/dtu-data-breach-may-affect-personal-information-of-200000-current-and-former-users/
MITRE ATT&CK T1078: https://attack.mitre.org/techniques/T1078/
MITRE ATT&CK T1213: https://attack.mitre.org/techniques/T1213/
MITRE ATT&CK T1041: https://attack.mitre.org/techniques/T1041/
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor risks in their digital supply chain. Our platform enables continuous monitoring of vendor security posture, automated risk assessments, and actionable insights to support incident response and compliance efforts. For questions or further information, please contact us at info@rescana.com.



