Major Danish university hacked, 200,000 people potentially exposed
Stolen data can include full names, home addresses, and work email addresses.

Image by Cybernews
- Hackers accessed DTU’s identity system and downloaded data dating back to 2003.
- Up to 200,000 current and former users may be affected, including students, employees, guests, and partners.
- Potentially exposed data includes CPR numbers, names, addresses, profile photos, work emails, and some next-of-kin details.
- DTU urges affected people to watch for scams, change reused passwords, and consider a CPR credit alert.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers accessed the identity and access management system of the Technical University of Denmark (DTU) and downloaded a large amount of data, potentially affecting up to 200,000 current and former users.
Threat actors compromised DTU profiles and used them to access the university’s identity system, DTUBasen, which contains personal data dating back to 2003.
Although DTU said it cannot currently determine the exact number of those affected, the database holds records of approximately 40,000 active users and around 160,000 former users. These people may include current and former employees, students, guests, and external partners.
Which information was accessed?
Potentially affected information includes CPR numbers, full names, home addresses, profile photos, work email addresses and other employment details, as well as next-of-kin information where provided.
According to DTU, for former users, home addresses, profile pictures, and next-of-kin information are automatically deleted after six months, but DTUBasen retains CPR numbers and full names.
“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected. Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take,” said University Director Bjarke Bak Christensen.
The university added that the investigation is ongoing, and it will provide more information as soon as possible.
Keeping safe
Users are warned that personal information and CPR numbers can be used for identity fraud and phishing.
DTU is therefore urging anyone who has been an employee, student, guest, or external partner since 2003 to remain alert for suspicious messages, avoid approving unexpected login requests, and change passwords on services where they reused their DTU password. The university also recommends considering a credit alert against their CPR number.
DTU will notify most affected current and former students and employees directly via e-Boks, but it’s issuing a public notice to reach guests and those it cannot contact individually.
DTU works with the Danish Armed Forces and the defence industry on drone technology and has a significant defence and security research program, although there is currently no indication that the attack was connected to this work.