DTU has identified a serious personal data breach involving DTU's identity and access management system, DTUBasen. In a targeted cyberattack, unauthorised persons gained access to the system and downloaded a large amount of data.
DTU's IT incident response team has contained the attack and has been working with external specialists to investigate its extent.
Unfortunately, DTU has to acknowledge that it is not possible to determine precisely what information was downloaded or how many people have been affected.
"This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected. Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take," says University Director Bjarke Bak Christensen.
"Our own investigations and those of the authorities are continuing, and we will provide information openly and as quickly as possible as we learn more."
What we know now
The attack involved unauthorised persons compromising DTU profiles and using them to gain access to DTUBasen. This gave them access to personal data dating back to 2003.
The incident has been reported to the Danish Data Protection Agency and referred to the relevant authorities for further investigation. In parallel, DTU is investigating the course of events together with external specialists.
DTU cannot determine how many users have been affected by the attack, but DTUBasen contains information relating to approximately 40,000 active users and approximately 160,000 former users.
Those potentially affected may therefore include current and former employees, students, guests, and external partners.
For active users, the information may include:
- Danish civil registration number (CPR number), full name, home address, and profile picture
- work email address, job title, office location, and other work-related information
- name, relationship, and telephone number of next of kin, if the user has registered this information
For former users, home addresses, profile pictures, and information about next of kin are automatically deleted after six months. However, DTUBasen continues to contain information including CPR numbers and full names.
If CPR numbers and other personal data have fallen into the hands of unauthorised persons, the information could potentially be used for identity fraud. The information could also make phishing attempts and other forms of fraud more convincing.
What you should do
If you are, or have been at any time since 2003, an employee, student, guest, or external partner at DTU, information about you may be included in the data breach.
DTU therefore recommends that you:
- be particularly alert to suspicious emails, text messages, and telephone calls, including when the sender or caller appears to know information about you or your connection to DTU
- do not disclose passwords or other confidential information in response to unexpected enquiries
- do not approve unexpected login or authentication requests
- change your password on services where you have reused your DTU password
- consider registering a credit alert against your CPR number at Borger.dk (in Danish)
If you have name and address protection, you should be particularly vigilant. If information about your name and address has fallen into the hands of unauthorised persons, this may increase the risk of unwanted contact, being located, or other forms of harassment.