Somebody who finished a degree at the Technical University of Denmark in 2008 has not thought about their student profile in eighteen years. They did not keep a login. They will not get a letter. But their name, their CPR number, and the phone number of a parent they once listed as next of kin sat in a DTU system until the week somebody downloaded it. That is the shape of the DTU data breach: the people with the most exposure are the ones who left.
Confirmation: confirmed by DTU, which announced the attack in its own news release on Friday, October 2, 2026.
What happened in the DTU data breach
Attackers compromised DTU user profiles first. Then they used those profiles to reach DTUBasen, the university’s identity and access management system. From there they downloaded what DTU describes as a larger amount of data, covering anyone who has been an employee, student, guest, or external partner since 2003.
The university puts the exposure at up to 200,000 people. That splits into roughly 40,000 active users and around 160,000 former ones, according to BleepingComputer’s report. DTU has also said plainly that it cannot determine precisely what was taken. University director Bjarke Bak Christensen called it a serious attack against DTU, and said the first priority was to clarify the scope and make sure affected people know how to respond.
Notification runs through e-Boks, Denmark’s official digital mail service, and it reaches people whose CPR numbers DTU still holds. Former students are the gap. Many of them will read about this breach rather than be told about it, as The Copenhagen Post noted.
What was exposed, and what each item is worth
For active users the list runs long. CPR numbers, which are Denmark’s personal identification numbers. Full names, home addresses, and profile pictures. Work email addresses, job titles, and office locations. Where a user had supplied next-of-kin details, those came along too: a name, the relationship, a telephone number.
The CPR number is the item to worry about first. It is the key to Danish public and financial services, so a fraudster who holds one alongside a matching name and address can attempt identity fraud with much better odds. The home address turns a generic scam into a local one. The next-of-kin record does quieter damage, because it hands a caller a family member to name.
Then there is the work email address, and it is the part that keeps working after everything else has been locked down. An address paired with a job title and an employer is raw material for a targeted phish. DTU said as much itself when it warned users about suspicious emails, texts, and phone calls.
Why the DTU data breach began with one stolen login
The DTU data breach is a credential story rather than an exotic exploit. Somebody held working DTU profiles, and those profiles were enough to walk into the system that holds everyone else’s records.
That pattern is the ordinary one. A password exists, the password leaks somewhere else, and the same address-and-password pair gets tried until it opens something. Because people reuse credentials across services, one leaked login is rarely worth just one account. The reason this matters so much for email in particular is that an inbox is the reset route into nearly everything else a person owns.
What to do now
Most of this has nothing to do with us.
- Assume you were in scope if you passed through DTU after 2003, including as a guest
- Treat any contact that mentions DTU as suspicious for the next few months. A phish
- Tell the next of kin you listed. They did not give DTU their phone number, you did,
- Put a password manager on every account that still uses a password, with one unique
- Turn on the strongest sign-in each account offers. Where a service supports passkeys
or a contractor. Watch e-Boks if you have a Danish CPR number on file there.
built on this data will know your old department and your job title. Verify by calling back on a number you looked up yourself.
and they have no reason to expect a call that name-drops you.
password each. This breach started with credentials, so that is the habit it argues for.
or hardware keys, take them over codes sent by text.
How OptMsg changes this exposure
OptMsg did not stop this, and it could not have. The data went out of a university’s systems, not out of anybody’s inbox. What an inbox changes is the second wave.
Two mechanisms are worth naming at their real size. First, an OptMsg account has no password, so a password leaked from another site cannot be tried on the inbox. Because email is the reset-and-recovery route into most other accounts, a door that a stolen credential cannot open tends to keep the accounts behind it shut as well. Second, mail from a sender you have not approved goes to Trash instead of your Inbox, and it auto-deletes after 30 days. The follow-up phish dressed up as DTU or e-Boks lands there.
Here is what that argument does not cover, stated plainly. Nothing in it touches a compromised device, a live phishing page you type your details into, or an attacker holding your unlocked phone. A CPR number already sitting in somebody’s database is beyond its reach too. What it narrows is the blast radius on your side of the breach, and that is the whole of the claim.
If the inbox is the part that worries you after a week like this one, read how OptMsg handles sign-in and senders, or start an account and see what a quiet inbox feels like.
Create Your Account
Your Inbox. Your Rules.
Frequently asked questions
Was I affected by the DTU data breach? If you have been an employee, student, guest, or external partner of DTU at any point since 2003, treat yourself as in scope. DTU says it cannot determine precisely which records were downloaded, so the safe assumption is the broad one.
Will DTU tell me directly? Only if it still holds your CPR number, in which case notice arrives through e-Boks. Former students are the group most likely to get no direct notice at all.
Were passwords stolen in the DTU data breach? Passwords are not on the list of exposed data categories DTU has described. The attack used compromised DTU profiles to get in, so the credential problem sits at the entry point rather than in the stolen file.
What is the realistic risk from a CPR number plus an address? Identity fraud attempts, and far more convincing phishing. DTU itself warned users about suspicious emails, texts, and calls for exactly this reason.
Does changing my email address help? It helps with the second wave rather than the first. The CPR number is already out, but a new address that only accepts mail from senders you approved gives the follow-up scam nowhere to land.
Sources
- BleepingComputer, Danish university DTU breach exposes data of up to 200,000 people, 2026-10-03 — https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/
- The Copenhagen Post, DTU data breach may affect personal information of 200,000 current and former users, 2026-10-02 — https://cphpost.dk/2026-10-02/life-in-denmark/dtu-data-breach-may-affect-personal-information-of-200000-current-and-former-users/
- The Local Denmark, Hacker attack at DTU could affect up to 200,000 people, 2026-10-02 — https://www.thelocal.dk/20261002/hacker-attack-at-dtu-could-affect-up-to-200000-people
Previous in Breach Breakdown: Frontline Education Data Breach: Your School's HR Vendor Had Your Social Security Number
Next in Breach Breakdown: The Denmark CPR Data Breach Took the One Number Nobody Can Reissue