Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot of data, which could impact about 200,000 current and past users. Threat actors broke into DTU profiles and used them to get into the university’s identity system, DTUBasen, which has personal data from 2003.
DTU cannot say how many are affected right now, but their database has records for about 40,000 active users and about 160,000 former users. These users may include current and past employees, students, guests, and outside partners.
Which information was accessed?
Potentially affected information includes CPR numbers, full names, home addresses, profile pictures, work email addresses, job details, and next-of-kin information if given.
DTU says that for past users, home addresses, profile pictures, and next-of-kin information get deleted after six months. However, DTUBasen keeps CPR numbers and full names.
“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected. Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take,” said University Director Bjarke Bak Christensen.
The university said the investigation is still happening, and will share more details soon.
Keeping safe
Users are warned that personal information and CPR numbers can be used for identity fraud and phishing.
DTU is asking everyone who has worked, studied, visited, or partnered with them since 2003 to watch out for suspicious messages, not to approve unexpected login requests, and to change passwords on services where they used their DTU password. The university also suggests setting up a credit alert for their CPR number.
DTU will inform most affected current and former students and employees directly through e-Boks. It is also giving a public notice to reach guests and people it cannot contact one by one.
DTU collaborates with the Danish Armed Forces and the defence industry on drone tech. They also have a big defence and security research program. However, there is no sign that the attack was linked to this work.
InfoSecBulletin Cybersecurity for mankind
