Opens in a new tab

DTU hack could expose data on 200,000 people

Friday 2nd October 2026 on 17:45 in Denmark

cybersecurity, data breach, DTU

A cyberattack on the Technical University of Denmark (DTU) could have exposed personal information about as many as 200,000 current and former people, cybersecurity professor Jens Myrup Pedersen told DR, calling it a serious data breach.

The information may include names, Danish personal identification numbers, home addresses and details about people’s relationships with others. The attackers also had access to personal data in DTU’s user database, which goes back to 2003.

DTU said its identity and access management systems were affected, but it did not yet know exactly what information had been accessed or how many people were affected. The university’s IT director, Mads Henrik Bang, said the attack took place in several waves and was first detected on September 20. The data relates to students, employees and people connected to the university as guests.

Pedersen said an attack affecting as many as 200,000 people was large and serious, rating it eight out of 10. He said Denmark had not seen an attack of similar size for several years, going back to the mid-2010s.

He warned that the data could be used in phishing attempts, with scammers posing as people whose information was accessed, or as people they know. He said access to databases should be restricted and systems should alert administrators if unusually large amounts of data are extracted. He also said two-factor authentication should be required.

DTU said it was sorry the breach had occurred. University director Bjarke Bak Christensen said the university’s priorities were to establish the scale of the incident, limit its consequences and notify affected people about how to respond. DTU said it would share information openly and as quickly as possible.

Source 
(via DR)