← All news
Data BreachIdentity SecurityData Protection

Hackers Used Stolen Credentials to Download 20 Years of Records From a Danish University's Identity System, Exposing Up to 200,000 People

Obiguard Research Team·October 5, 2026·4 min read

The Technical University of Denmark (DTU) has disclosed that attackers used compromised credentials to get into its identity and access management system and download a dataset covering more than two decades. The university says up to 200,000 people may be affected, according to BleepingComputer's report.

What was taken

The system involved is DTUBasen, DTU's identity and access management platform. Anyone affiliated with the university since 2003 may have records in it. DTU estimates about 40,000 current users and 160,000 former users, and says it cannot determine precisely how many people were affected.

According to the disclosure, the exposed data includes:

  • Danish civil registration numbers (CPR numbers)
  • Full names, home addresses and profile pictures
  • Work email addresses, job titles and office locations
  • Names, relationships and phone numbers of next of kin

No group has been named, and the university has not described how the credentials were obtained. DTU has notified affected people through e-Boks, Denmark's official digital mailbox, and published a public notice for those it could not reach. It advises recipients to watch for phishing, change passwords and place credit alerts on their CPR numbers. University Director Bjarke Bak Christensen called it "a serious attack on DTU".

Why this one matters

Most of the 160,000 former users left DTU long ago. Their records were still sitting in a live system, reachable with a single working login. The size of the exposure came less from the attack than from how much data the system kept.

Three lessons follow:

  1. An identity system holds more than logins. Once it stores national ID numbers, home addresses and next-of-kin details, it is a personal-data store and needs the controls of one.
  2. Retention is a security control. Data you no longer need is a liability with no business value. Every former student or employee record is something to protect and to disclose.
  3. Phishing follows a breach. A list of names, addresses and next-of-kin details lets an attacker write a convincing message. This is the pattern we covered in the campaign targeting AI policy experts, and DTU's own advice to recipients is to expect it.

The AI angle: personal data is easy to copy somewhere new

Universities and large employers hold exactly this kind of data, and the people who handle it increasingly work alongside AI tools. An administrator asked to tidy a spreadsheet of staff records, or draft letters to former students, can paste CPR numbers, addresses and next-of-kin details into a chat assistant in seconds. That creates a second copy of the data outside the system built to protect it, and no access review or retention schedule covers it.

Obiguard Governance AI addresses that part of the problem. Guardrails on prompts and responses can detect personal identifiers such as national ID numbers, addresses and phone numbers before they reach a model, and block, redact or flag them according to policy your organisation sets. Every request is recorded in an audit trail, so when a regulator or a data protection officer asks where personal data went, you can answer from the record.

It does not stop credential theft, and it would not have prevented this breach. Strong authentication, monitoring of identity systems and disciplined retention are still the answer there. What it does is keep your AI usage from adding new copies of regulated data to a problem that is already large.

The question to take away

If someone on your team pasted a spreadsheet of personal records into an AI assistant today, would your organisation know, and would anything have stopped it?

Explore Governance AI or talk to us about setting data-handling policy for the AI tools your people already use.

How Obiguard helps

Turn this into enforced policy, not just awareness.

Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.

See how it works →