Up to 200,000 current and former students, employees and guests at the Technical University of Denmark may have had personal data stolen in a hacker attack, including names, CPR numbers and addresses going back to 2003.
DTU in Kongens Lyngby confirmed on October 2, 2026, that it had suffered what it called a serious breach of personal data security. As DR reports, information on up to 200,000 current and former people connected to the university may be in the hands of hackers.
According to DTU’s IT director, Mads Henrik Bang, the stolen data concerns students, employees and guest relations at the university. He told DR that the attack took place in several waves and was first detected on September 20.
What DTU says was accessed
In its own breach notification, DTU says unauthorized people gained access to its identity and access management system. The compromised database, DTUBasen, holds personal data dating back to 2003, including full names and CPR numbers. Other information may include addresses and next-of-kin details.
DTU states that the database contains information on roughly 40,000 active users and 160,000 former users. Those affected may include current and former employees, students, guests and external partners. The university says it cannot yet determine precisely what was downloaded or how many people are involved.
Per DTU, compromised DTU profiles were used to gain access to DTUBasen. The university says its incident response team has contained the attack and is investigating with external specialists. The incident has been reported to the Danish Data Protection Agency, Datatilsynet, and referred to relevant authorities.
DTU’s university director, Bjarke Bak Christensen, said in a press release that the university regrets what happened. According to the statement, the first priority has been to establish the scope, limit the consequences and make sure those affected are told how to respond.
Cybersecurity expert places it at eight out of ten
Jens Myrup Pedersen, professor of cybersecurity at Aarhus University, told DR there is no doubt this is a very large data leak affecting a great many people. He said you have to go back to the middle of the 2010s to find an attack of this size in Denmark, and placed it at eight on a scale of ten.
As noted by Pedersen, the data can be used for phishing attacks in which criminals pose as the people whose details were taken. He said this can affect both those in the hacked databases and people they know. He also argued there should be limits on who can access such data and how much can be extracted without raising an alarm, as well as two-step approval.
Bang said he finds the incident very serious and described it as an advanced attack. He urged people to stay as secure as possible and to be alert. DTU says it will inform affected people openly and as quickly as possible. The university has previously not been alone in this: a similar data breach at the University of Copenhagen drew ministerial attention.
What the DTU breach means for international students and staff
The CPR number is the Danish civil registration number used for tax, banking, healthcare and public self-service logins. DTU is one of Denmark’s largest technical higher education institutions and enrolls international students and researchers, many of whom received a CPR number on arrival. Because DTUBasen goes back to 2003, people who left Denmark years ago may still appear in the data.
TV 2 reports that DTU will notify current and former employees and almost all current and former students. The same coverage says DTU recommends changing passwords where the DTU password has been reused, rejecting unexpected authentication requests, and staying alert to suspicious messages and calls. What remains unknown, by DTU’s own account, is exactly which records were downloaded and how many individuals are affected.





