• 6 min read

A campus IAM breach creates a two-decade identity risk

Compromised DTU credentials exposed an IAM system spanning more than two decades, potentially putting up to 200,000 people at risk of identity fraud and targeted phishing.

A campus IAM breach creates a two-decade identity risk

Image: BleepingComputer

The Technical University of Denmark’s breach shows that an identity and access management system is more than a login service. If attackers obtain credentials for a central directory, they can access a historical record of a community’s identities, employment relationships, physical locations, and recovery contacts. DTU says an attacker used compromised credentials to enter DTUBasen, its IAM system, and download a large quantity of data tied to as many as 200,000 current and former users.

The university cannot determine precisely which records were taken or how many people were affected. The system contains data for nearly 40,000 active users and about 160,000 former users, creating a potential exposure pool that reaches back to 2003. The incident is documented in DTU’s official personal-data-breach notification.

“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected.”

— Bjarke Bak Christensen, University Director, DTU

An IAM directory with more than account data

For active users, DTUBasen may contain Danish civil registration numbers, known as CPR numbers, along with full names, home addresses, profile photos, work email addresses, job titles, office locations, and other employment details. CPR numbers can strengthen an attacker’s identity-fraud attempts when combined with contact and address data.

Apple’s iOS 26 patch fixes an actively exploited zero-day

Recommended reading

Apple’s iOS 26 patch fixes an actively exploited zero-day

Sergey Kuznetsov • • 7 min read

The directory also held next-of-kin records where active users had provided them. Those entries could include a contact’s name, relationship to the DTU user, and telephone number. This extends the potential impact beyond people who studied or worked at the university: a convincing social-engineering attempt can exploit a family relationship as readily as an office title.

User population in DTUBasenApproximate recordsData-retention detail described by DTU
Active usersNearly 40,000May include CPR number, identity, contact, workplace, and next-of-kin data
Former usersAround 160,000Home address, profile photo, and next-of-kin information are automatically deleted after six months

The automatic six-month deletion rule applies to those specific fields for former users; it does not establish that every former-user record was empty or that all other directory information had been removed. Nor does it establish which state any record was in when the attacker accessed the system. DTU cannot identify the downloaded data, which is the central operational problem.

Credentials were the entry point, but the access path is undisclosed

DTU has said the attacker entered using compromised credentials. It has not disclosed how those credentials were stolen, whether multifactor authentication was required for DTUBasen access, whether the account had elevated privileges, or how the download was detected. It also has not said what controls, if any, limited bulk exports from the identity system.

The difference between a compromised ordinary account and a privileged directory-management account determines the likely blast radius. The reported access to a large volume of data spanning active and former users shows that the compromised identity could reach high-value records. The information disclosed does not establish whether the attacker bypassed a control or used legitimate access available to that account.

The university warns that stolen CPR numbers and associated personal information could be used for identity fraud and more credible phishing. That risk does not depend on attackers possessing passwords. A caller or email sender who knows a person’s DTU relationship, home address, job title, and family contact can make a fraudulent request appear more legitimate than generic spam.

DTU advises affected people to treat unexpected messages, phone calls, login prompts, and authentication requests with suspicion; not to provide passwords or sensitive information in reply; to change passwords reused on other services; and to place a credit alert on an affected CPR number. The password-reuse advice is a precaution, but DTU has not said that account passwords were included in the data taken.

Notification will not reach every affected person directly

DTU plans to use e-Boks, Denmark’s official digital mailbox service, to notify people it can reach. It says it will contact all current and former employees, but it cannot directly notify every current and former student whose CPR number it holds. Its public notice is meant to reach former employees, students, guests, and external partners who may have been associated with DTU since 2003.

The university says it retains CPR numbers only for a small number of guests and external partners. It does not retain CPR numbers for next-of-kin contacts entered in DTUBasen. That narrows one category of risk, but next-of-kin names, relationships, and phone numbers can still be useful for impersonation or coercive phishing when paired with a DTU user’s other details.

Direct notification will not reach everyone affected. People whose connection to DTU ended years ago may be most likely to miss a direct alert, and a university account and its directory record may no longer be top of mind for them. A public notice can expand awareness, but it cannot verify that former students and affiliates receive it.

Nonfinancial data remains operationally valuable

The DTU disclosure is one example of attackers seeking identity and contact information rather than payment records. In August, France said attackers obtained tax, business, and cadastral data connected to 678,000 people and organizations, while account credentials were not exposed. The France tax-authority breach showed why the absence of credentials does not make an identity-data incident low impact.

The scale is smaller than the up to 8.7 million people affected in the Manchester Airports Group incident reported on August 29, 2026, but the record types differ. Manchester disclosed contact, postcode, and vehicle information tied to services such as parking and lounges; DTU’s directory may include CPR numbers and employment relationships. A government identity number combined with organizational affiliation is useful for a targeted fraud operation, even when no financial information is named in the disclosure.

IAM platforms need to be treated as sensitive repositories with long-lived personal data, not just as authentication systems. Access scope, bulk-download controls, monitoring, and retention policies can limit what a single valid login exposes. DTU’s disclosure does not say which of those safeguards were in place, so their effectiveness cannot be assessed from outside the university.

Anyone who was a DTU employee, student, guest, or external partner from 2003 onward may need to assume that personal details linked to that affiliation could be used to tailor fraud attempts. Until DTU can establish what was downloaded and which account was used, the breach’s scope remains bounded by the directory’s maximum population rather than a confirmed victim count.

Frequently asked questions

How many people may be affected by the DTU breach?+

DTU says data belonging to up to 200,000 people may have been exposed. Its identity system holds records for nearly 40,000 active users and around 160,000 former users.

What data may have been exposed in the DTU attack?+

For active users, potentially exposed data includes CPR numbers, names, addresses, profile pictures, work emails, job titles, office locations, and some next-of-kin contact information.

Who can receive a direct DTU breach notification?+

DTU says it will notify all current and former employees through e-Boks, but not all current and former students whose CPR numbers it holds can be contacted directly.

Sergey Kuznetsov

Editor-in-Chief

Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.

/ Keep reading