Cyberattack on DTU: Notification of a personal data breach
Hackers have attacked and gained access to DTU’s identity and access management system and downloaded a large amount of data. Information relating to up to 200,000 current and former users may have been affected.
Friday 02 October 2026
DTU has identified a serious personal data breach involving DTU’s identity and access management system, DTUBasen. In a targeted cyberattack, unauthorised persons gained access to the system and downloaded a large amount of data.
DTU’s IT incident response team has contained the attack and has been working with external specialists to investigate its extent.
Unfortunately, DTU has to acknowledge that it is not possible to determine precisely what information was downloaded or how many people have been affected.
“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected. Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take,” says University Director Bjarke Bak Christensen.
“Our own investigations and those of the authorities are continuing, and we will provide information openly and as quickly as possible as we learn more.”
What we know now
The attack involved unauthorised persons compromising DTU profiles and using them to gain access to DTUBasen. This gave them access to personal data dating back to 2003.
The incident has been reported to the Danish Data Protection Agency and referred to the relevant authorities for further investigation. In parallel, DTU is investigating the course of events together with external specialists.
DTU cannot determine how many users have been affected by the attack, but DTUBasen contains information relating to approximately 40,000 active users and approximately 160,000 former users.
Those potentially affected may therefore include current and former employees, students, guests, and external partners.
For active users, the information may include:
Danish civil registration number (CPR number), full name, home address, and profile picture
work email address, job title, office location, and other work-related information
name, relationship, and telephone number of next of kin, if the user has registered this information
For former users, home addresses, profile pictures, and information about next of kin are automatically deleted after six months. However, DTUBasen continues to contain information including CPR numbers and full names.
If CPR numbers and other personal data have fallen into the hands of unauthorised persons, the information could potentially be used for identity fraud. The information could also make phishing attempts and other forms of fraud more convincing.
What you should do
If you are, or have been at any time since 2003, an employee, student, guest, or external partner at DTU, information about you may be included in the data breach.
DTU therefore recommends that you:
be particularly alert to suspicious emails, text messages, and telephone calls, including when the sender or caller appears to know information about you or your connection to DTU
do not disclose passwords or other confidential information in response to unexpected enquiries
do not approve unexpected login or authentication requests
change your password on services where you have reused your DTU password
consider registering a credit alert against your CPR number at Borger.dk (in Danish)
If you have name and address protection, you should be particularly vigilant. If information about your name and address has fallen into the hands of unauthorised persons, this may increase the risk of unwanted contact, being located, or other forms of harassment.
You can read more about how to protect yourself at Sikkerdigital.dk (in Danish).
What DTU is doing
Current and former employees, as well as almost all current and former students for whom DTU holds a CPR number, will be notified via e-Boks. They will therefore receive a personal notification as soon as possible.
However, DTU only holds CPR numbers for a small number of guests and external partners and does not hold CPR numbers for next of kin whose contact details have been registered in DTUBasen.
DTU is therefore issuing this public notice at the same time to reach people whom DTU is unable to contact directly. Please share it with former students, employees, guests, or external partners who may be affected.
Further information
If you have questions about whether you may be affected or what steps you should take, you can contact DTU via IT-information at DTU.
DTU will update this page as significant new information becomes available.