2026 DTU — DTUBasen IAM breach; up to ~200k current/former users (CPR)
Data compromised
Active users: CPR, name, home address, profile picture, work email, job title, office location, next-of-kin name/relationship/phone when registered; former users: CPR and name retained (address/photo/next-of-kin deleted after 6 months)
Technical writeup
Verified DTU public notice (Friday 2 October 2026) and BleepingComputer coverage (Oct 3). Attackers compromised DTU profiles and accessed DTUBasen IAM, downloading a large volume of identity data dating to 2003. DTU cannot precisely quantify what was taken; DTUBasen holds ~40,000 active and ~160,000 former users (up to ~200,000). Incident reported to the Danish Data Protection Agency; e-Boks notifications for most CPR holders; public notice for guests/partners/next of kin without CPR on file. companyConfirmed true; recordsAffected 200000 (university upper-bound cohort).
Root cause
Compromised DTU credentials used to access DTUBasen identity and access management system; large data download