Skip to content
See the World Through ScienceA project of ALLATRA

Denmark's Technical University Says Hackers Downloaded Data on up to 200,000 People

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A yellow brick university building with rows of windows and awnings, framed by trees on a sunny day at the Technical University of Denmark.
The university's campus sits in Kongens Lyngby, north of Copenhagen. DTU's notice covers people recorded in its central account system since 2003."Building 321, Technical University of Denmark, 2016-07-20" by Finn Årup Nielsen, via wikimedia, CC-BY-SA-4.0

The Technical University of Denmark said on Oct. 2, 2026, that attackers compromised user profiles, used them to reach DTUBasen, the system that holds its user records and controls access to its services, and downloaded a large amount of data. Information on up to 200,000 current and former users may have been affected, and the records go back to 2003.

DTU's breach notice says records for active users can include a full name, home address, profile picture, work details, next-of-kin contacts and a CPR number, the Danish civil registration number used for banking, health care and government services. DTU said that in unauthorized hands such data could be used for identity fraud and could make phishing attempts more convincing.

DTU said it cannot determine precisely what was downloaded or how many people were affected. The 200,000 is the size of the system rather than a count of victims: DTUBasen holds records on about 40,000 active and about 160,000 former users, and anyone who has been an employee, student, guest or external partner since 2003 may be included. For former users, home addresses, profile pictures and next-of-kin details are deleted automatically after six months, while CPR numbers and full names remain.

DTU said its incident response team has contained the attack and that it is investigating the extent with outside specialists. The breach was reported to the Danish Data Protection Agency and referred to other authorities. The notice does not say who was behind the attack, how the profiles were compromised, or whether the data has surfaced anywhere.

DTU said current and former employees, and almost all students past and present for whom it holds a CPR number, will be notified personally through e-Boks, Denmark's official digital mail service. It issued the public notice to reach people it cannot contact directly. Its advice to users is to treat unexpected calls, emails and texts as suspicious even when the sender seems to know their DTU connection, never to approve an unexpected login request, to change any password reused from DTU, and to consider registering a credit alert against their CPR number.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Denmark's Technical University Says Hackers Downloaded Data on up to 200,000 People

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.