
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.
The university says the attacker used compromised credentials to log into DTUBasen, its identity and access management (IAM) system, allowing access to more than two decades of user data.
In a disclosure on Friday, DTU confirmed that it cannot “determine precisely what information was downloaded or how many people have been affected.”
However, the Danish university notes that DTUBasen stores information for nearly 40,000 active users and around 160,000 former users.
Next of kin data also exposed
Potentially exposed information for current users includes Danish civil registration numbers (CPR), full names, home addresses, and profile pictures, as well as work email addresses, job titles, office locations, and other employment-related details.
The dataset also contained the names, relationships, and telephone numbers of users’ next of kin, when provided by active users.
DTU notes that in the case of former users, details about home addresses, profile pictures, and information about next of kin are automatically deleted after six months.
“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected,” says University Director Bjarke Bak Christensen.
“Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take,” the director added.
DTU warns that cybercriminals could use the exposed CPR numbers and other personal data for identity fraud and to make phishing attacks more convincing.
Not all notified directly
Potentially impacted individuals will be notified through e-Boks, the official mailbox system that DTU uses for sharing documents and notices with students and staff.
However, the university says it will notify all current and former employees, but not all current and former students whose CPR numbers are held by DTU.
“DTU only holds CPR numbers for a small number of guests and external partners and does not hold CPR numbers for next of kin whose contact details have been registered in DTUBasen,” the organization says.
The public dicslosure is part of DTU’s effort to reach potentially affected individuals it cannot contact directly, and the university is urging people to share it with former employees, students, guests, and external partners.
The organization says that anyone who has been an employee, student, guest, or external partner of DTU since 2003 may be affected by the data breach.
They are advised to be cautious of emails, text messages, and phone calls from individuals who appear to know about their connection with DTU or have access to personal information about them.
Passwords and sensitive information should not be disclosed in replies to unexpected communications, and sudden authentication requests or logins should be treated as suspicious.
Additionally, it is recommended to change the passwords for any other services that use the same credentials as the DTU account and place a credit alert on the affected CPR number.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
