Technical University of Denmark confirms large-scale data breach affecting 200,000 individuals

The Technical University of Denmark disclosed a significant security breach in which attackers exploited compromised credentials to access its identity and access management system, potentially exposing personal information for up to 200,000 current and former users. The compromised data includes sensitive identifiers such as Danish civil registration numbers, home addresses, employment details, and emergency contact information. The university warned that exposed personal data could be leveraged for identity fraud and targeted phishing attacks.
The breach occurred through attackers obtaining valid login credentials and exploiting them to access DTU's core identity management infrastructure, which had accumulated records spanning more than twenty years of institutional history. The university faces significant uncertainty about the breach's full scope, as investigators cannot definitively quantify either the volume of data exfiltrated or the precise number of individuals whose information was compromised. This ambiguity stems from the IAM system's role as a central repository for both active participants and departed users, with retention policies differing between employee and student categories.
The exposure of Danish civil registration numbers alongside personal identifiers could enable widespread identity theft and sophisticated social engineering campaigns targeting affected individuals. Current and former employees face heightened risk due to complete data retention, while the university's inability to directly contact all potentially affected former students may leave some unaware of protective measures they should undertake. The incident underscores how centralized identity systems, while operationally efficient, create concentrated repositories of sensitive information that warrant substantial security investment and incident response planning.