Technical University of Denmark reports data breach impacting as many as 200,000 accounts
The Technical University of Denmark (DTU) disclosed that a cyberattack could have exposed personal data of up to 200,000 people after perpetrators breached its identity and access management system and retrieved a large dataset.
The university stated that the intruders accessed the platform governing user authentication and permissions, extracting files that hold information on students, faculty, staff and potentially external partners. DTU noted the incident was detected through regular monitoring and that an internal probe, aided by outside specialists, has commenced.
Although the complete list of compromised records remains undisclosed, officials warned that the leaked data may encompass names, email addresses, university ID numbers and other details normally kept in an identity store. DTU has not verified if passwords or additional authentication tokens were among the pilfered files.
In recent years, higher‑education campuses have grown into appealing targets for cybercriminals, chiefly because centralized authentication services grant access to numerous campus assets. Comparable breaches at European universities have underscored the difficulty of safeguarding legacy IAM systems that frequently connect to both cloud‑based and on‑premise applications.
DTU has started informing possibly impacted individuals and is recommending they reset passwords, activate two‑factor authentication when feasible, and stay alert for dubious messages. The institution also reported the breach to Danish data‑protection regulators and is working with law‑enforcement bodies to identify the attackers.
Going forward, the university intends to perform an extensive forensic audit, strengthen its security framework, and evaluate adherence to the EU’s General Data Protection Regulation. Analysts argue that this incident may trigger wider examination of identity‑management protocols throughout academic networks, and they advise anyone whose information might have been exposed to watch their accounts for any misuse.
Comments (0)
Be the first to comment.
Join the discussion