DTU’s Breach Warning Reaches Beyond Its Notification List
DTU’s 2 October notice says compromised profiles gave intruders access to DTUBasen and a large data download. The system holds about 40,000 active and 160,000 former-user records, but DTU cannot identify every affected person or field. Employees, students, guests and external partners since 2003 may be affected.
Current records may include CPR numbers, addresses and next-of-kin contacts. Former records retain CPR numbers and names; addresses, photos and next-of-kin details are deleted after six months.
DTU cannot directly notify many guests, external partners or next of kin. It advises rejecting unexpected authentication prompts, changing reused passwords, watching for phishing and considering a CPR credit alert.
Source: DTU.


