The Technical University of Denmark (DTU) has disclosed a major data breach that may have exposed personal information belonging to as many as 200,000 current and former users. Hackers reportedly accessed DTUBasen, the university’s identity and access management system, after obtaining valid credentials. The system contains records collected over more than two decades, raising concerns about identity theft, targeted phishing and other forms of fraud.
DTU said it cannot yet determine exactly which information attackers downloaded or how many people have been affected. However, the database contains details linked to nearly 40,000 active users and approximately 160,000 former users. Information related to current users may include Danish civil registration numbers, full names, home addresses, profile photographs, work email addresses, job titles, office locations and other employment details.
The breach may also have exposed emergency-contact information submitted by active users. This could include the names, relationships and phone numbers of next of kin. DTU noted that information about home addresses, profile pictures and next of kin belonging to former users is automatically deleted after six months. University Director Bjarke Bak Christensen described the incident as a serious attack and apologised for the uncertainty caused to potentially affected individuals.
DTU plans to notify potentially impacted people through e-Boks, Denmark’s official digital mailbox service. The university said it will contact current and former employees, although not every student whose information may be stored in the system will receive a direct notification. Anyone who has been a DTU employee, student, guest or external partner since 2003 could potentially be affected, according to the university’s public warning.
The university is advising affected individuals to remain alert for suspicious emails, text messages and phone calls that mention their connection with DTU or contain accurate personal details. People should avoid sharing passwords, personal information or authentication codes in response to unexpected requests. They should also change reused passwords on other services and consider placing a credit alert on their affected civil registration number. The incident highlights how compromised credentials can give attackers access to extensive historical records, even when an organisation’s main systems remain operational.
Read the original article:
