Select a theme from the list.
Insights

From our experts

Latest
TerminalFix Lures Turn Victims Into Gateways for Covert Network AccessCritical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskDTU Identity System Breach Puts Two Decades of Personal Data at RiskPhishing Campaign Turns Legitimate RMM Software Into a Double BackdoorAndroid 17 Closes a Favorite Doorway for Banking MalwareFrontline Education Breach Exposes Sensitive School Employee RecordsSophos Pitches Continuous Security Governance to Organizations Without CISOsPentagon Personnel Breach Exposes Data on More Than Three Million PeopleMicrosoft Warns That AI Is Compressing Cyberattacks From Days to SecondsOpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelAI-Speed Intruder Chains Zammad Zero-Days Into Root AccessCrafted Emails Turn Zimbra Servers Into Command-Execution GatewaysTerminalFix Lures Turn Victims Into Gateways for Covert Network AccessCritical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskDTU Identity System Breach Puts Two Decades of Personal Data at RiskPhishing Campaign Turns Legitimate RMM Software Into a Double BackdoorAndroid 17 Closes a Favorite Doorway for Banking MalwareFrontline Education Breach Exposes Sensitive School Employee RecordsSophos Pitches Continuous Security Governance to Organizations Without CISOsPentagon Personnel Breach Exposes Data on More Than Three Million PeopleMicrosoft Warns That AI Is Compressing Cyberattacks From Days to SecondsOpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelAI-Speed Intruder Chains Zammad Zero-Days Into Root AccessCrafted Emails Turn Zimbra Servers Into Command-Execution Gateways
Security Insight

DTU Identity System Breach Puts Two Decades of Personal Data at Risk

DTU Identity System Breach Puts Two Decades of Personal Data at Risk
Photo by Ann H on Pexels

The Technical University of Denmark says attackers used compromised credentials to enter its identity and access management system, potentially exposing information connected to approximately 200,000 current and former users. The affected records span more than two decades and may include national identification numbers, addresses, employment details and next-of-kin information. The incident demonstrates how identity platforms can become unusually valuable targets when historical accounts and personal records remain concentrated in one system.

The Technical University of Denmark is investigating a significant breach of DTUBasen, the identity and access management platform supporting its academic and employment community. According to the university, an attacker entered the system with compromised credentials and downloaded a large quantity of information, although investigators have not determined exactly which records were taken.

A Long History Creates a Large Exposure

DTUBasen contains information associated with nearly 40,000 active users and around 160,000 former users. Anyone who has worked, studied or maintained another formal relationship with DTU since 2003 may potentially be affected.

The information at risk varies by relationship and retention status. It may include names, Danish civil registration numbers, home and work addresses, profile photographs, email addresses, job titles and office details. Some active-user records also contain names, relationships and telephone numbers for next of kin.

This is more than a conventional account compromise. Identity management platforms frequently connect people, roles, departments and authentication processes. A successful intrusion can therefore expose both personal information and valuable organizational context that criminals can use to construct convincing impersonation attempts.

What Organizations Should Learn

  • Require phishing-resistant multifactor authentication for identity administrators and other privileged users.
  • Monitor unusual exports, bulk queries and access to large collections of historical records.
  • Remove obsolete accounts and reduce the amount of personal information retained for former users.
  • Separate administrative functions from ordinary user access and apply conditional access controls.
  • Prepare notification procedures for former employees and students who may no longer have active institutional contact details.

Potential victims should be cautious when receiving messages that reference their connection to DTU or contain accurate personal details. Knowledge of a job title, former department or family contact should not be treated as proof that a caller or sender is legitimate.

Expert View

In my view, the most important lesson is that identity infrastructure must be treated as a sensitive data repository, not merely as a login service. Universities often maintain long relationships with students, researchers, employees and external partners, which can produce decades of accumulated records. Strong authentication is essential, but organizations must also detect abnormal data access and regularly question whether older information still needs to remain online.

Talk to our team →

Latest

TerminalFix Lures Turn Victims Into Gateways for Covert Network AccessOct 4, 2026Critical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskOct 4, 2026DTU Identity System Breach Puts Two Decades of Personal Data at RiskOct 4, 2026Phishing Campaign Turns Legitimate RMM Software Into a Double BackdoorOct 3, 2026Android 17 Closes a Favorite Doorway for Banking MalwareOct 3, 2026Frontline Education Breach Exposes Sensitive School Employee RecordsOct 3, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards