The Technical University of Denmark (DTU) confirmed on Friday that an attacker used stolen credentials to enter DTUBasen, its identity system, and download a large volume of data. I run AliasFleet, an email-alias service: one forwarding address per website, so the next leak names its source, not your identity. That is the lens I read this breach through. In scope: nearly 40,000 active users and around 160,000 former users, going back to 2003. (I am working from English reporting of DTU's Danish-language disclosure.)
Most breaches I write about are a company's customer database. This one is different. The attacker breached the system where identities themselves are kept. That makes the data pairing here unusually useful for fraud: a national ID number next to a work email address, for up to 200,000 people.
The vault was the target
DTUBasen is not a side project or a marketing database. It is DTU's central identity and access management platform: the system that knows who everyone is. The attacker logged in with compromised credentials, and the system could not tell the difference between them and a legitimate user. From there they could browse more than two decades of user records.
No exploit chain has been reported, and DTU has disclosed no intrusion timeline. One credential, used the way it was designed to be used. That is how a growing share of breaches now happen: the stolen login is the exploit.
What is worse, DTU says it "cannot determine precisely what information was downloaded or how many people have been affected." Read that twice. So the figure of 200,000 is the ceiling, not the count. The university cannot say whether your record was downloaded. Nobody can.
What was exposed
| Exposed data | Current users (~40,000) | Former users (~160,000) |
|---|---|---|
| Full name, CPR number, work email | Yes | Yes |
| Home address, profile photo | Yes | Auto-deleted after 6 months |
| Next-of-kin name, relationship, phone | Yes, if provided | Auto-deleted after 6 months |
| Job title, office location | Yes | Not specified by DTU |
What did the attacker actually take?
DTU cannot say precisely. The attacker downloaded data from DTUBasen, which holds CPR numbers, names, home addresses, profile photos, work email addresses and job details for current users, plus next-of-kin contact details. For former users, addresses, photos and next-of-kin data are auto-deleted after six months. The 200,000 figure is everyone in scope, not the confirmed victim count.
CPR numbers are the dangerous part
Most breach data goes stale. Passwords get reset, cards get reissued, addresses change. A CPR number does not. It is Denmark's national identification number, assigned for life, used across taxes, healthcare, banking and government services. You cannot rotate it.
So when DTU says the exposed CPR numbers could be used for identity fraud, that is not boilerplate. A CPR number plus a name, home address and a work email address is close to a complete identity kit. It is enough to attempt account takeovers, apply for services in someone else's name, or build the kind of patient, personalised fraud that unfolds over months instead of hours.
The next-of-kin data makes the picture uglier. Names, relationships and telephone numbers of the people you listed as emergency contacts. Attackers do not need that for account fraud. They need it for the other game: calling your mother pretending to be you, or calling you pretending to be the police with your details. This dataset was built, by accident of its contents, for impersonation in both directions.
There is one small mercy in the design. For former users, DTU deletes home addresses, profile pictures and next-of-kin details after six months. The exposure for people who left years ago is likely narrower. Work email addresses, names and CPR numbers are the fields that stick around.
Why is a CPR number worse than a password?
A password can be reset and a card reissued. A CPR number is Denmark's lifelong national ID, used across taxes, healthcare, banking and government. Paired with a name, home address and work email, it is close to a complete identity kit: enough for account takeovers, fraudulent applications, or slow, personalised fraud that unfolds over months.
The notification has a blind spot
DTU will notify affected people through e-Boks, Denmark's official digital mailbox. All current and former employees get reached. Not all current and former students whose CPR numbers it holds. Some people will only learn about this through the public disclosure, which is why DTU is asking people to pass the word to former students, guests and external partners.
Think about who that leaves out. A student who graduated in 2019 and now lives in Berlin or London. Their data sits in the 160,000 former users. Their Danish e-Boks mailbox may be something they have not opened in years, if it still works at all. They are supposed to hear about it because a friend shared the news. That is a notification strategy with a real hole in it, and the people in the hole are the ones most likely to be confused by a sudden email "from DTU" in a language they barely read anymore. Perfect phishing bait, if an attacker has the same thought.
If you have any DTU history, act this week
Work through these in order. The university's advice is worth following directly, with one addition of my own at step 4.
- Change your DTU password, and the password anywhere you reused it. The entry point was compromised credentials, and reuse is what turns one theft into several.
- Place a credit alert on your CPR number through Denmark's credit reporting services, to flag new applications made in your name.
- Treat incoming contact with suspicion in proportion to how much it knows about you. An email that knows your employee title, your office location, or your student years is not necessarily legitimate: that is exactly the data that was taken. Verify through a channel you already trust, never by replying to the message that arrived.
- Warn your listed next of kin. They did not sign up for any of this and will not be watching for it. A thirty-second conversation now is cheaper than a convincing phone scam later.
- Check Have I Been Pwned and enable its breach notifications so future leaks reach you directly. The full response checklist is in our breach response guide.
Beware of emails, texts and calls that show knowledge of your DTU connection. Never disclose passwords or sensitive information in replies.
Make the next phish announce itself
Here is where my bias shows, and I will say it plainly: this breach cannot be prevented by anything a victim did. No alias, no password manager, no VPN stops an attacker's stolen credential from working against a university's identity system. The data is out. The question is only what the fraud costs you.
Phishing is the delivery step, and that step can be made to fail loudly. The attacker has your work email address, so the phish will arrive at that address and look right. But suppose you had given DTU's systems, or the services around them, unique aliases instead: then an email about your DTU account arriving at an alias you never gave DTU is fraud by construction. You do not need to inspect headers or squint at sender domains. The To field names the source, and a mismatch names the lie. Our leak-tracing guide explains the mechanism.
I am not pretending this is a complete answer. If the attacker calls your bank with your CPR number, no email alias in the world helps. And a university account is not something most people can move to an alias; it is assigned to you. The honest claim is narrower: aliases shrink the attack surface of the phishing second wave, which is where most of the actual money gets lost after a breach like this. A unique alias per service turns your inbox into a place where impersonation has to work harder.
I run AliasFleet, which does exactly this: one alias per website, forwarding to your real inbox, killable in one click. The docs explain the mechanics, and the free tier covers 10 active aliases. DTU's warning, that criminals will make phishing more convincing with your own data, is the strongest argument I know for not handing every service the same address.
Top comments (0)