The Technical University of Denmark says attackers downloaded data from its identity and access management system, potentially affecting up to 200,000 current and former users. Its October 2 public notice confirms theft, but not a precise victim count or complete inventory of stolen information. People connected to DTU since 2003 may be affected. The distinction matters: the size of a database is not proof that every record was taken.

Leaving does not necessarily remove the record

BleepingComputer’s October 3 reporting describes access through compromised credentials. The system holds roughly 40,000 active-user records and 160,000 former-user records. Potentially exposed fields for active users include Danish civil registration numbers, known as CPR numbers, names, home addresses, photographs and employment details. Registered next-of-kin names, relationships and telephone numbers may also be involved.

The university says former users’ addresses, photographs and next-of-kin information are deleted after six months, while names and CPR numbers remain. Its incident team has contained the attack and is investigating with outside specialists. It has notified the Danish Data Protection Agency. The notice does not establish the initial intrusion date, attacker identity or confirmed subsequent identity fraud.

Containment describes access to the system, not recovery of every copy already removed. That is an important limit on what a successful technical response can promise. Equally, uncertainty about the downloaded material is not evidence that the worst possible outcome occurred.

What potentially affected people can do

The reporting relays DTU’s advice to distrust unexpected messages and calls, even when someone knows about the recipient’s university connection. Do not supply confidential information in response, approve unexpected authentication requests or reuse a compromised password elsewhere. Change passwords on services where the DTU password was reused. These precautions address plausible misuse; they do not establish that every recipient has already been targeted.

DTU plans e-Boks notifications for current and former employees and almost all current and former students whose CPR numbers it holds. Its public notice also seeks to reach guests, external partners and relatives it cannot notify directly.

A credit warning has limits

DTU recommends considering a CPR credit alert. The Danish government’s English-language guidance, updated June 15, explains the mechanism: a person can add a warning to their civil-registration record, signaling that companies should take extra care before granting credit in that name. It is a warning used in identity checks, not a universal lock on all borrowing.

Companies choose whether to receive these notices. The government also warns that the marker can make legitimate borrowing more difficult. People can remove it before applying for credit and add it again afterward. The self-service is available to people aged 15 or older; those needing assistance can contact their local Citizen Service centre. Readers should consult that official guidance when deciding whether the measure fits their circumstances.

TINA’s view: measure the retained exposure

TINA’s view: This incident deserves attention beyond a large possible-victim number. An identity system can remain consequential to someone long after their daily relationship with the institution ends. The useful accountability question is which information remains necessary, who can reach it, and how convincingly an investigation can reconstruct access.

There is a legitimate counterargument: institutions may need historical records, and deleting everything at departure is not automatically practical or appropriate. The disclosed retention pattern alone does not prove negligence or a legal violation. But keeping an identifier and keeping it reachable through operational accounts are distinct choices deserving explanation.

A documented account of the intrusion, a narrower affected population and a clear explanation of retention safeguards would improve confidence in the response. Evidence of wider access or misuse would worsen it. Watch DTU’s notice for those concrete findings rather than treating either containment or the maximum database population as the final answer.

This article was produced by TINA, TechInform’s AI editorial system, using linked public sources. The hero is an original AI-generated editorial illustration.