Back www.dtu.dk Cyberattack On Dtu Notification Of A Personal Data Breach
Hackers have attacked and gained access to DTU’s identity and access management system and downloaded a large amount of data. Information relating to up to 200,000 current and former users may have been affected.
DTU has identified a serious personal data breach involving DTU’s identity and access management system, DTUBasen. In a targeted cyberattack, unauthorised persons gained access to the system and downloaded a large amount of data.
DTU’s IT incident response team has contained the attack and has been working with external specialists to investigate its extent.
Unfortunately, DTU has to acknowledge that it is not possible to determine precisely what information was downloaded or how many people have been affected.
“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected. Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take,” says University Director Bjarke Bak Christensen.
The attack involved unauthorised persons compromising DTU profiles and using them to gain access to DTUBasen. This gave them access to personal data dating back to 2003.
The incident has been reported to the Danish Data Protection Agency and referred to the relevant authorities for further investigation. In parallel, DTU is investigating the course of events together with external specialists.
DTU cannot determine how many users have been affected by the attack, but DTUBasen contains information relating to approximately 40,000 active users and approximately 160,000 former users.
Those potentially affected may therefore include current and former employees, students, guests, and external partners.
For active users, the information may include:
Danish civil registration number (CPR number), full name, address, and profile picture
work email address, job title, office location, and other work-related information
name, relationship, and telephone number of of kin, if the user has registered this information
For former users, addresses, profile pictures, and information of kin are automatically deleted after six months. However, DTUBasen continues to contain information including CPR numbers and full names.
If CPR numbers and other personal data have fallen into the hands of unauthorised persons, the information could potentially be used for identity fraud. The information could also make phishing attempts and other forms of fraud more convincing.
If you are, or have been at any time since 2003, an employee, student, guest, or external partner at DTU, information you may be included in the data breach. DTU therefore recommends that you:
be particularly alert to suspicious emails, text messages, and telephone calls, including when the sender or caller appears to know information you or your connection to DTU
do not disclose passwords or other confidential information in response to unexpected enquiries
do not approve unexpected login or authentication requests
change your password on services where you have reused your DTU password
consider registering a credit alert against your CPR number at Borger.dk (in Danish)
If you have name and address protection, you should be particularly vigilant. If information your name and address has fallen into the hands of unauthorised persons, this may increase the risk of unwanted , being located, or other forms of harassment.
Current and former employees, as well as almost all current and former students for whom DTU holds a CPR number, will be notified via e-Boks. They will therefore receive a personal notification as soon as possible.
However, DTU only holds CPR numbers for a small number of guests and external partners and does not hold CPR numbers for of kin whose details have been registered in DTUBasen.
DTU is therefore issuing this public notice at the same time to reach people whom DTU is unable to directly. Please it with former students, employees, guests, or external partners who may be affected.
If you have questions whether you may be affected or what steps you should take, you can DTU via IT-information at DTU .
DTU will update this page as significant new information becomes available.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
