Protect.Computer
NEWS

Danish University DTU Breach May Expose 200,000 People

· 1 min read · Identity theft Got hacked
Danish University DTU Breach May Expose 200,000 People

The Technical University of Denmark (DTU) says information on up to 200,000 people may have been exposed after an attacker logged into DTUBasen, its identity and access management system, with compromised credentials and downloaded a large amount of data. DTU says it cannot determine precisely what was downloaded or how many people are affected. The system holds records for nearly 40,000 active users and around 160,000 former users, going back more than two decades.

For current users, the exposed data may include Danish civil registration (CPR) numbers, full names, home addresses, profile pictures, work email addresses, job titles and office locations, plus the names, relationships and phone numbers of next of kin where provided. For former users, home addresses, profile pictures and next-of-kin details are automatically deleted after six months. DTU warns the data could fuel identity fraud and make phishing more convincing. Notices go out through e-Boks, but DTU says it will notify all current and former employees and not all current and former students, so it published a public disclosure and asked people to share it.

How to check if you’re affected

Affected products and accounts are tied to DTU’s identity system, DTUBasen: anyone who has been an employee, student, guest or external partner of DTU since 2003 may be affected. Watch for an e-Boks notice from DTU. DTU advises treating emails, texts and calls from people who seem to know your DTU connection or personal details as suspicious, never sharing passwords or sensitive information in reply, changing the password on any service that reused your DTU password, and placing a credit alert on your CPR number.

Sources

Related reading