Up to 200,000 people may have had personal data taken from the Technical University of Denmark, which announced the breach on Friday, October 3, 2026. The figure is DTU’s ceiling, not a confirmed count: the university said it cannot determine exactly what was downloaded or how many people are affected. As reported by BleepingComputer, about 40,000 of those people are current users of its systems and roughly 160,000 are former ones.
The data came out of DTUBasen, the identity and access management system, and the exposed fields include Danish civil registration (CPR) numbers. University Director Bjarke Bak Christensen called it “a serious attack on DTU” and said the university “deeply regrets the uncertainty it is causing.”
DTUBasen and the Stolen Credentials
According to BleepingComputer’s report on the disclosure, the attackers got in with compromised credentials and used them to reach DTUBasen, then downloaded a substantial amount of data that spans more than two decades. An identity system is a rich target because it holds the directory a university uses to know who is a student, an employee or a retiree, and it holds that directory for everyone who was ever enrolled in it.
DTU is a technical university in Kongens Lyngby with a history that goes back to 1829. The report says the downloaded data spans more than two decades, and former users outnumber current ones four to one in the estimate, so a directory that keeps former users is the reason an incident today can reach people who left long ago.
Counting 200,000: People, Not Records
The unit matters here. BleepingComputer’s account describes up to 200,000 individuals, split between roughly 40,000 current users and roughly 160,000 former users. It does not give a number of database records, files or rows, so the unit is persons, and the total is a ceiling on persons rather than a tally of records.
The exposed fields differ from person to person. They include CPR numbers, full names, home addresses, profile pictures, work email addresses, job titles and office locations. The set also includes next-of-kin details: names, relationships and phone numbers. The reported figure speaks of users, so it does not say whether the relatives named in those next-of-kin fields are counted inside the 200,000 or sit on top of it.
The CPR number is the sensitive item. DTU warned that criminals could exploit the exposed numbers for identity fraud and for carefully crafted phishing attacks. A civil registration number is a fixed identifier that cannot be reset the way a password can, and here it sits in the same directory as names and home addresses.
The two groups also face different practical exposure. Employees, current and former, are the people DTU said it would contact directly, and their records carry job titles, office locations and work email addresses alongside the CPR number. For students, the university’s route is public disclosure and e-Boks, so someone who studied at DTU years ago and never gave the university a current address learns of the breach only if they see the announcement or open the mailbox. That gap between a directory that lasts for decades and a notification that depends on a current contact point is the practical weakness in a 160,000-person former-user population.
Notification Under GDPR Rules
Denmark is covered by the EU’s data protection regulation, and Article 33 requires a controller to notify the supervisory authority within 72 hours of becoming aware of a breach. The notice is meant to state the approximate number of data subjects and of personal data records concerned. That is the framework in which a university gives an estimate as loose as “up to” 200,000: the rule asks for approximate numbers and allows information to be supplied in phases. Beyond the headcount, the same article calls for a description of the breach’s nature, the likely consequences and the measures taken or planned, and it says a controller that misses the 72-hour window must explain the delay. DTU’s public warning about identity fraud and phishing is the kind of consequence statement that framework contemplates. The Danish regulator’s own pages sit at Datatilsynet.
Telling the people affected is a second duty. Article 34 requires notice to individuals when a breach is likely to cause high risk to them, and it allows public communication when direct contact would take disproportionate effort. DTU appears to have used both. Current and former employees are to be contacted directly, while many current and former students are expected to learn through the public announcement and through e-Boks, the official Danish electronic mailbox system.
DTU’s own statement leaves the final count open: the university said it cannot yet establish what was downloaded, so 200,000 stays a maximum until that work is done.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell
- Hurricane Hunter radar shows four warning signs that a tropical cyclone is about to strengthen, a University of Miami study found
- NTSB report details how a family of four died when their plane’s nose suddenly pitched up
- Doctors warn a silent liver disease now affects one in three American adults