Danmarks Tekniske Universitet says hackers broke into its central user database, DTUBasen, and that personal information on up to 200,000 current and former students, employees, guests and partners may be affected.
DTU announced the breach in a press release on October 2, 2026, as reported by DR. The university describes it as a serious breach of personal data security, carried out against its identity and access management system.
According to DTU, intruders compromised DTU profiles and used them to reach DTUBasen. From there, they retrieved a larger volume of data. The university says the records in the database stretch back to 2003.
University director Bjarke Bak Christensen says the attack is a serious one against DTU. He apologizes for the uncertainty it creates for the people whose information may be affected, per DR’s reporting.
What DTU says it does and does not know
DTU states that it cannot determine precisely which information was downloaded. It also cannot say exactly how many people are affected. DTUBasen holds data on roughly 40,000 active users and about 160,000 former users.
The potentially affected group includes current and former employees, students, guests and external partners. DTU says the attack has been contained. Its own investigation and the authorities’ investigation are continuing.
The university warns that if CPR numbers and other personal data have reached unauthorized hands, the information could potentially be used for identity fraud. It also notes the data could make phishing attempts and other misuse appear more credible.
Politiken reports the same figure of up to 200,000 potentially affected users and quotes Christensen calling the attack serious. Berlingske confirms the university’s announcement of the same number.
Ekstra Bladet adds that DTU said a large amount of data was taken from its identity and access management system. The outlet also notes the university could not yet identify the precise data or the number of people involved.
How DTU is contacting affected people
DTU says current and former employees will be notified through e-Boks. Almost all current and former students for whom the university holds a CPR number will be notified the same way. Christensen says DTU will inform openly and as quickly as possible as more becomes known.
The university holds CPR numbers for only a few guests and partners, and none for relatives whose contact details are registered in DTUBasen. For that reason, DTU says it cannot contact those people directly. The university points anyone with questions to its IT information pages.
What the DTU breach means for international students and researchers
DTU is one of the largest technical universities in Denmark and hosts large numbers of international students, PhD fellows and visiting researchers. Because the affected records go back to 2003, people who studied or worked at DTU years ago and have since left Denmark may also be in the database. DTU says it cannot yet specify which data was taken.
Two Danish systems matter here. The CPR number is the personal registration number issued to residents and used across Danish public services and banking. e-Boks is the national digital mailbox used by public authorities, and it is where DTU says notifications will be sent. Anyone who has studied at a Danish institution and still has access to e-Boks through MitID can therefore receive the notice there, while people without a registered CPR number at DTU cannot be contacted directly, according to the university.
For internationals who have left the country or never held a CPR number, the practical consequence is that DTU may have no way to reach them. DTU says it will publish further information as its investigation progresses, and it has not stated what categories of data beyond CPR numbers were in DTUBasen. Those involved in higher education in Denmark can follow DTU’s IT information page for updates, since the university has not set a date for its next statement.







