The Technical University of Denmark (DTU) says attackers used compromised credentials to access its DTUBasen identity and access management system and potentially exposed data for up to 200,000 users. The breach may have revealed CPR numbers, names, addresses, profile photos, and next-of-kin details, prompting warnings about identity fraud and targeted phishing. #DTU #DTUBasen #CPRnumbers
Keypoints
- Hackers used stolen credentials to enter DTU’s DTUBasen IAM system.
- Up to 200,000 current and former users may have had data exposed.
- Exposed data may include CPR numbers, names, addresses, and profile pictures.
- Next-of-kin names, relationships, and phone numbers may also have been accessed.
- DTU is notifying affected people and warning them about phishing and identity fraud.