MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-03 · via BleepingComputer

Technical University of Denmark confirms large-scale data breach affecting 200,000 individuals

Image via BleepingComputer
Image via BleepingComputer

The Technical University of Denmark disclosed a significant security breach in which attackers exploited compromised credentials to access its identity and access management system, potentially exposing personal information for up to 200,000 current and former users. The compromised data includes sensitive identifiers such as Danish civil registration numbers, home addresses, employment details, and emergency contact information. The university warned that exposed personal data could be leveraged for identity fraud and targeted phishing attacks.

Expanded Detail

The breach occurred through attackers obtaining valid login credentials and exploiting them to access DTU's core identity management infrastructure, which had accumulated records spanning more than twenty years of institutional history. The university faces significant uncertainty about the breach's full scope, as investigators cannot definitively quantify either the volume of data exfiltrated or the precise number of individuals whose information was compromised. This ambiguity stems from the IAM system's role as a central repository for both active participants and departed users, with retention policies differing between employee and student categories.

Context

The exposure of Danish civil registration numbers alongside personal identifiers could enable widespread identity theft and sophisticated social engineering campaigns targeting affected individuals. Current and former employees face heightened risk due to complete data retention, while the university's inability to directly contact all potentially affected former students may leave some unaware of protective measures they should undertake. The incident underscores how centralized identity systems, while operationally efficient, create concentrated repositories of sensitive information that warrant substantial security investment and incident response planning.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Third-party software flaw leads to theft of school employee records at Frontline Education · Cybersecurity
Federal Agents Allegedly Stored Protest Observers' Data in Palantir System · Cybersecurity
Patched Security Vulnerability Exposed ChatGPT Users to Complete Account Compromise · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Danish university DTU breach exposes data of up to 200,000 people.” Browse more stories.