Security2 publishers2 min readPublished Updated
Compromised login to DTU's identity system put up to 200,000 people's records at risk
Technical University of Denmark says a login with compromised credentials to its IAM system may have exposed data on up to 200,000 people. The records reach back to 2003, and active users' entries include CPR national ID numbers that DTU warns can be used for identity fraud.
The Watch · Security desk

What happened
- DTU said in its Friday disclosure that it cannot determine precisely what information was downloaded or how many people were affected.
- DTUBasen holds records on nearly 40,000 active users and around 160,000 former users.
- Home addresses, profile pictures and next-of-kin details of former users are deleted automatically after six months, according to DTU.
- DTU is asking people to pass its disclosure to former employees, students, guests and external partners it cannot contact directly.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint DTU's 200,000 ceiling is the entire DTUBasen population, so until the university learns what was downloaded it has to handle every current and former user as exposed.
- exposure Relatives listed as next of kin have phone numbers in the exposed data but no CPR number on file at DTU, so they depend on the public notice reaching them.
- cost The cleanup DTU recommends, a credit alert on the CPR number and new passwords on any service sharing the DTU credentials, is work each affected person has to do.
Former users are about 80 percent of the people in DTUBasen [1]. The six-month purge removes some fields from their entries but leaves the entries in the identity system [7][4]. DTU puts the exposure window at anyone who has been an employee, student, guest or external partner since 2003 [11].
The richer records belong to active users. DTU lists CPR numbers, full names, home addresses, profile pictures, work email addresses, job titles and office locations among their exposed data [5]. Where active users registered next of kin, the system also held those relatives' names, relationships and telephone numbers [6]. A caller working from that set can open with the user's name, a relative's name and how the two are related [6]. DTU warns that criminals could use the CPR numbers and other personal data for identity fraud and to make phishing more convincing [9]. Its advice is to distrust emails, texts and calls from anyone who seems to know about a person's DTU connection, and to treat sudden authentication requests or logins as suspicious [12].
"This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected," University Director Bjarke Bak Christensen said [8].
The intrusion path is short. An attacker used compromised credentials to log into the IAM system, and that access reached more than two decades of user data [2]. The argument for keeping less in an identity system follows from DTU's own inventory. The directory that governs logins also stored national ID numbers, home addresses and family phone numbers [5][6].
The argument for tighter controls on the account that was used cannot yet be tested. The disclosure does not say whose credentials they were, how they were obtained, whether the account required a second factor, or who used them.
What to watch
- DTU stating whose credentials were used and whether that account required a second factor.
- A leak-site post or sale offer for DTUBasen data would show what was actually taken.
- Any regulator finding on why CPR numbers and next-of-kin contacts sat in DTU's identity system.