$ techbeacon▋
Breaches

DTU reports potential exposure of up to 200,000 users' data in cyber breach

DTU reports potential exposure of up to 200,000 users' data in cyber breach

Denmark’s Technical University (DTU) disclosed that a cyber intrusion may have compromised personal information linked to as many as 200,000 individuals after attackers infiltrated its identity and access management (IAM) platform.

The university said the breach was discovered when unusual activity was detected on the IAM system, prompting an internal investigation that revealed a large volume of data had been copied. The compromised records are believed to include usernames, email addresses and other authentication details used by students, faculty, staff and alumni.

DTU, one of Europe’s leading engineering schools, confirmed that the intrusion appears to have been carried out by external actors who gained privileged access to the system. While the exact method of entry has not been disclosed, security experts note that IAM solutions are attractive targets because they store the credentials that grant access to a wide range of campus services.

In accordance with Denmark’s data‑protection regulations and the EU’s General Data Protection Regulation (GDPR), the university has notified the Danish Data Protection Agency and is cooperating with law‑enforcement authorities to identify the perpetrators. DTU also warned affected users to monitor their accounts for suspicious activity and to change passwords on any services that may share the same credentials.

The incident adds to a growing list of higher‑education breaches worldwide, where attackers exploit single sign‑on and directory services to harvest large datasets. Cyber‑security analysts say that the fallout can extend beyond immediate credential theft, potentially enabling phishing campaigns, identity fraud, or further infiltration of connected systems.

DTU’s chief information officer said the institution is conducting a thorough forensic review and will implement additional safeguards, including multi‑factor authentication and tighter network segmentation. The university has pledged to keep the community informed as more details become available and to provide support resources for anyone who may be impacted.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related