The Technical University of Denmark (DTU) has disclosed that attackers used compromised credentials to get into its identity and access management system and download a dataset covering more than two decades. The university says up to 200,000 people may be affected, according to BleepingComputer's report.
The system involved is DTUBasen, DTU's identity and access management platform. Anyone affiliated with the university since 2003 may have records in it. DTU estimates about 40,000 current users and 160,000 former users, and says it cannot determine precisely how many people were affected.
According to the disclosure, the exposed data includes:
No group has been named, and the university has not described how the credentials were obtained. DTU has notified affected people through e-Boks, Denmark's official digital mailbox, and published a public notice for those it could not reach. It advises recipients to watch for phishing, change passwords and place credit alerts on their CPR numbers. University Director Bjarke Bak Christensen called it "a serious attack on DTU".
Most of the 160,000 former users left DTU long ago. Their records were still sitting in a live system, reachable with a single working login. The size of the exposure came less from the attack than from how much data the system kept.
Three lessons follow:
Universities and large employers hold exactly this kind of data, and the people who handle it increasingly work alongside AI tools. An administrator asked to tidy a spreadsheet of staff records, or draft letters to former students, can paste CPR numbers, addresses and next-of-kin details into a chat assistant in seconds. That creates a second copy of the data outside the system built to protect it, and no access review or retention schedule covers it.
Obiguard Governance AI addresses that part of the problem. Guardrails on prompts and responses can detect personal identifiers such as national ID numbers, addresses and phone numbers before they reach a model, and block, redact or flag them according to policy your organisation sets. Every request is recorded in an audit trail, so when a regulator or a data protection officer asks where personal data went, you can answer from the record.
It does not stop credential theft, and it would not have prevented this breach. Strong authentication, monitoring of identity systems and disciplined retention are still the answer there. What it does is keep your AI usage from adding new copies of regulated data to a problem that is already large.
If someone on your team pasted a spreadsheet of personal records into an AI assistant today, would your organisation know, and would anything have stopped it?
Explore Governance AI or talk to us about setting data-handling policy for the AI tools your people already use.
Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.
See how it works →