DTU breach: IAM data on up to 200,000 users
Technical University of Denmark identity store downloaded

DTU breach: IAM data on up to 200,000 users

The Technical University of Denmark said on 2 October 2026 that attackers got into DTUBasen, its identity and access management system, and downloaded a large amount of data. Information on up to 200,000 current and former users may be exposed. DTU has notified the Danish Data Protection Agency.

What happened

DTU says unauthorized people compromised user profiles and used them to reach the identity store. The downloaded records go back to 2003. The university cannot yet say how many people are actually in the stolen set. DTUBasen holds about 40,000 active users and about 160,000 former users: staff, students, guests, and external partners.

For active users the exposed fields can include a Danish civil registration number, full name, home address, profile picture, work email, job title, office location, and next-of-kin name and phone if that was registered. For former users, home address, photo, and next-of-kin data are deleted after six months, but the civil registration number and full name are retained.

Who is affected

  • Current and former DTU employees, students, guests, and partners whose records sit in DTUBasen.
  • Anyone whose Danish CPR number was stored there, including records dating to 2003.
  • The lesson for other organisations is the identity system itself. A helpdesk or directory that can mint or read every account is a single point of failure.

What to do now

If you run a campus, MSP, or client identity store, list who can export it and alert on bulk reads. DTU's notice is a reminder that IAM is not a back-office database. Restrict export rights, keep former-user identifiers on a shorter retention clock where the law allows, and make sure a compromised user profile cannot read the whole directory. Partners who share staff data with a university portal should ask whether their records were in scope.

Source: Technical University of Denmark, Cyberattack on DTU: notification of a personal data breach.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-102489: Zammad zero-day chain, KEV due 5 October
Session hijack to root on internet-facing Zammad helpdesks