Technical University of Denmark confirms breach affecting up to 200,000 accounts
The Technical University of Denmark (DTU) announced that a cyber intrusion may have compromised personal information belonging to as many as 200,000 individuals after attackers penetrated its identity and access management platform and extracted a sizable data set.
According to the university, the unauthorized actors gained entry to the system that controls user authentication and permissions, downloading files that contain details of students, faculty, staff and possibly external collaborators. DTU said the breach was discovered during routine monitoring and that an internal investigation, supported by external experts, is now under way.
While the full inventory of exposed records has not been disclosed, officials indicated that the compromised material could include names, email addresses, university identification numbers and other data typically stored in an identity repository. The university has not confirmed whether passwords or other authentication tokens were part of the stolen files.
Higher‑education institutions have become attractive targets for cybercriminals in recent years, largely because centralized authentication services hold the keys to a wide range of campus resources. Similar attacks on European universities have highlighted the challenges of protecting legacy IAM solutions that often integrate with multiple cloud and on‑premise applications.
DTU has begun notifying potentially affected users and is urging them to change passwords, enable two‑factor authentication where possible, and remain vigilant for suspicious communications. The school also reported the incident to Danish data‑protection authorities and is cooperating with law‑enforcement agencies to trace the perpetrators.
Looking ahead, the university plans to conduct a thorough forensic review, reinforce its security architecture, and assess compliance with the European Union’s General Data Protection Regulation. Experts suggest that the breach could prompt broader scrutiny of identity‑management practices across academic networks, while individuals whose data may have been exposed are advised to monitor accounts for any signs of misuse.
Comments (0)
Be the first to comment.
Join the discussion