DTU's disclosure on Friday confirmed that the breach exposed data including Danish civil registration numbers (CPR), full names, home addresses, profile pictures, work email addresses, job titles, office locations and next-of-kin details for active users. For former users, home addresses, profile pictures and next-of-kin information are normally deleted after six months, but the university cannot rule out that some of this data was taken.
The university stated it cannot determine precisely what information was downloaded or how many individuals have been affected. DTUBasen stores records for nearly 40,000 active users and around 160,000 former users.
"This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected," said University Director Bjarke Bak Christensen. "Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take."
DTU is notifying potentially affected individuals through e-Boks, Denmark's official digital mailbox system. The university said it will notify all current and former employees but not all current and former students who have CPR numbers on file. It urged anyone who has been an employee, student, guest or external partner of DTU since 2003 to be cautious of unsolicited communications that could exploit the stolen data for phishing or identity fraud.
Affected individuals are advised to be wary of emails, text messages and calls that reference their connection to DTU, to avoid disclosing passwords or sensitive information in response to such communications, and to treat unexpected authentication requests as suspicious. Changing passwords on any other services that use the same credentials as the DTU account and placing a credit alert on the affected CPR number are also recommended.