Threat reportData BreachTL-2026-3306

Danish PII Exposures (DTU DTUBasen Breach and CPR Register Misuse) Increase Risk of Targeted Phishing

mediumACTIVE

Danish PII Exposures (DTU DTUBasen Breach and CPR Register (TL-2026-3306), also tracked as DTUBasen breach, is a medium-severity data breach, first published 2026-10-11. It has no confirmed attribution, affects Technical University of Denmark (DTU) DTUBasen identity and access, maps to 8 MITRE ATT&CK techniques (T1078, T1111, T1119), and is covered by 9 detection rules and 10 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
10Indicators of compromise

Key facts for TL-2026-3306

Threat ID
TL-2026-3306
Also known as
DTUBasen breach, CPR register breach
Severity
MEDIUM
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
education, government administration, general-public
Target regions
denmark, Europe
Detection rules
9
Indicators of compromise
10
Updates
2026-10-11 · revalidated 1× · latest source

How Danish PII Exposures (DTU DTUBasen Breach and CPR Register works

Two October 2026 Danish PII exposures: a DTU breach via compromised credentials into the DTUBasen IAM system (up to 200,000 current and former users) and misuse of a private company's legitimate CPR access exposing names, addresses and CPR numbers of about 8.8 million people. No threat actor or onward use of the data is confirmed, but the data enables targeted phishing and MitID lures.

DTU (Technical University of Denmark) disclosed on 2 October 2026 a personal data breach in DTUBasen, its identity and access management system. Unauthorized persons used compromised DTU user profiles/credentials to log into DTUBasen and downloaded a large volume of data spanning more than two decades. DTU says it cannot determine precisely what was downloaded or how many people are affected; up to 200,000 people are potentially impacted (about 40,000 active users and about 160,000 former users: students, employees, guests and partners). Exposed data for active users includes CPR numbers, names, addresses, profile pictures, work emails, job titles, office locations and next-of-kin details (names, relationships, phone numbers). For former users DTUBasen retains CPR numbers and full names; addresses, photos and next-of-kin data are deleted after six months. DTU contained the attack, engaged external specialists, notified Datatilsynet (Danish Data Protection Agency) and authorities, and notified employees via e-Boks.

Separately, the CPR administration noticed irregular activity on the evening of 2 October 2026 and established that searches took place during September 2026. An unauthorized party abused a private Danish company's legitimate access to the Central Person Register (CPR; access for private firms with a justified interest under section 38 of the CPR Act), staying within the query limits permitted to private companies. Names, addresses and 10-digit CPR numbers of about 8.8 million people (about 80% of roughly 11 million records, including living residents, emigrants and deceased persons) were exposed; people with name and address protection were not affected. The company's access was blocked, Datatilsynet was notified, police opened an investigation, and the responsible minister (Christina Egelund) informed Parliament's Business and Digitalisation Committee and requested a security review of the CPR system. Public disclosure was on 5 October 2026.

Truesec (6 October 2026) assesses that the combination of exposed identity data, organizational context (DTU affiliation, office location, job title, next-of-kin) and CPR numbers raises the risk of targeted phishing, social engineering, identity fraud and MitID-themed lures, including attempts to obtain one-time codes. No threat actor, malware, network indicator or confirmed acquisition or abuse of the data by a threat actor was identified in the sources. Severity is assigned on exposure scale and phishing risk. Defenders should treat DTU-affiliated and Danish-resident users as higher-risk targets for credential and MitID phishing, enforce phishing-resistant MFA, monitor for anomalous IAM logins and bulk directory downloads, and review third-party CPR access governance.

MITRE ATT&CK techniques used in TL-2026-3306

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing

Persistence

T1078 Valid Accounts

Credential Access

T1111 Multi-Factor Authentication Interception

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Affected products and versions in Danish PII Exposures (DTU DTUBasen Breach and CPR Register

  • Technical University of Denmark (DTU) — DTUBasen identity and access management system
    Vulnerable versions: Not applicable - credential compromise
  • Danish CPR Administration — Central Person Register (CPR) private-company access
    Vulnerable versions: Not applicable - misuse of legitimate access
    Fixed in: Misused company access revoked

Remediation for Danish PII Exposures (DTU DTUBasen Breach and CPR Register

Immediate actions

  • Treat unsolicited email, SMS and calls referencing DTU, MitID, CPR or borger.dk with heightened scrutiny and verify via official websites or published phone numbers
  • Never disclose MitID codes, one-time codes, passwords or payment details to unsolicited requesters
  • Change passwords on any service that reused DTU credentials
  • Register a credit alert (kreditadvarsel) via borger.dk if CPR misuse is a concern

Workarounds

  • Add phishing-awareness notices for DTU-affiliated staff and students
  • Enhance monitoring for suspicious identity and account activity

Longer-term hardening

  • Enforce phishing-resistant MFA on identity and access management platforms
  • Monitor IAM systems for anomalous logins and bulk downloads of directory or profile data
  • Review governance, monitoring and rate limiting for private-company access to national registers such as CPR
  • Minimize retention of CPR numbers and personal data for former users

Timeline of Danish PII Exposures (DTU DTUBasen Breach and CPR Register

  • Searches abusing a private Danish company's legitimate CPR access took place during September 2026, per the CPR administration.
  • DTU announced a personal data breach: compromised user profiles used to access DTUBasen and download data on up to 200,000 people.
  • CPR administration noticed irregular activity in the evening and blocked the company's access.
  • Over the weekend following detection, the private company's access to the CPR was shut off.
  • BleepingComputer and other outlets reported the DTU breach; DTU notified employees via e-Boks and could not reach all affected students.
  • Danish authorities publicly disclosed the CPR misuse affecting about 8.8 million people; police investigation opened and Datatilsynet case started; minister informed Parliament committee.
  • Citizens were directed to sikkerdigital.dk and the national Cyberhotline extended its hours (8 a.m. to midnight); the perpetrator was still not identified.
  • Truesec published an analysis of the two exposures warning of heightened targeted phishing and MitID lure risk.

Update history for TL-2026-3306

Sources cited for Danish PII Exposures (DTU DTUBasen Breach and CPR Register

Detection coverage for TL-2026-3306

As of 2026-10-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3306 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
10 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats