Computers

DTU Breach Exposes Data of Up to 200,000 Users via DTUBasen

Hackers used compromised credentials to reach the Technical University of Denmark's identity system; CPR numbers and addresses may be among the data.

The Technical University of Denmark (DTU) has disclosed that hackers accessed DTUBasen, its identity and access management system, using compromised credentials. According to bleepingcomputer.com, the university said information belonging to up to 200,000 users may have been exposed.

DTU said it cannot determine precisely what information was downloaded or how many people have been affected. DTUBasen stores records for nearly 40,000 active users and around 160,000 former users.

Potentially exposed data includes CPR numbers, full names, home addresses, profile pictures, work email addresses, job titles, office locations, and next-of-kin names and phone numbers.

DTU will notify current and former employees through e-Boks, but not all current and former students whose CPR numbers it holds. Anyone who has been an employee, student, guest or external partner of DTU since 2003 may be affected.

Quick answers

Who may be affected by the DTU data breach?

Anyone who has been an employee, student, guest or external partner of DTU since 2003, according to the university.

What data may have been exposed in the DTUBasen breach?

Potentially exposed data includes CPR numbers, full names, home addresses, profile pictures, work email addresses, job titles, office locations, and next-of-kin names and phone numbers.

How will DTU notify affected people?

DTU will notify current and former employees via e-Boks, but not all current and former students whose CPR numbers it holds.

Source