# Danish PII Exposures (DTU DTUBasen Breach and CPR Register Misuse) Increase Risk of Targeted Phishing

> Two October 2026 Danish PII exposures: a DTU breach via compromised credentials into the DTUBasen IAM system (up to 200,000 current and former users) and misuse of a private company's legitimate CPR access exposing names, addresses and CPR numbers of about 8.8 million people. No threat actor or onward use of the data is confirmed, but the data enables targeted phishing and MitID lures.

- **Published:** 2026-10-11T13:56:05Z
- **Last reviewed:** 2026-10-11T14:23:40.029Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3306
- **ID:** TL-2026-3306
- **Severity:** MEDIUM
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)

## Description

DTU (Technical University of Denmark) disclosed on 2 October 2026 a personal data breach in DTUBasen, its identity and access management system. Unauthorized persons used compromised DTU user profiles/credentials to log into DTUBasen and downloaded a large volume of data spanning more than two decades. DTU says it cannot determine precisely what was downloaded or how many people are affected; up to 200,000 people are potentially impacted (about 40,000 active users and about 160,000 former users: students, employees, guests and partners). Exposed data for active users includes CPR numbers, names, addresses, profile pictures, work emails, job titles, office locations and next-of-kin details (names, relationships, phone numbers). For former users DTUBasen retains CPR numbers and full names; addresses, photos and next-of-kin data are deleted after six months. DTU contained the attack, engaged external specialists, notified Datatilsynet (Danish Data Protection Agency) and authorities, and notified employees via e-Boks.

Separately, the CPR administration noticed irregular activity on the evening of 2 October 2026 and established that searches took place during September 2026. An unauthorized party abused a private Danish company's legitimate access to the Central Person Register (CPR; access for private firms with a justified interest under section 38 of the CPR Act), staying within the query limits permitted to private companies. Names, addresses and 10-digit CPR numbers of about 8.8 million people (about 80% of roughly 11 million records, including living residents, emigrants and deceased persons) were exposed; people with name and address protection were not affected. The company's access was blocked, Datatilsynet was notified, police opened an investigation, and the responsible minister (Christina Egelund) informed Parliament's Business and Digitalisation Committee and requested a security review of the CPR system. Public disclosure was on 5 October 2026.

Truesec (6 October 2026) assesses that the combination of exposed identity data, organizational context (DTU affiliation, office location, job title, next-of-kin) and CPR numbers raises the risk of targeted phishing, social engineering, identity fraud and MitID-themed lures, including attempts to obtain one-time codes. No threat actor, malware, network indicator or confirmed acquisition or abuse of the data by a threat actor was identified in the sources. Severity is assigned on exposure scale and phishing risk. Defenders should treat DTU-affiliated and Danish-resident users as higher-risk targets for credential and MitID phishing, enforce phishing-resistant MFA, monitor for anomalous IAM logins and bulk directory downloads, and review third-party CPR access governance.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1078 Valid Accounts
- T1213 Data from Information Repositories
- T1589 Gather Victim Identity Information
- T1566 Phishing
- T1598 Phishing for Information
- T1111 Multi-Factor Authentication Interception
- T1199 Trusted Relationship
- T1119 Automated Collection

## Sources

- [Recent Danish PII Exposures Increase Risk of Targeted Phishing Campaigns](https://www.truesec.com/hub/blog/recent-danish-pii-exposures-increase-risk-of-targeted-phishing-campaigns)
- [Cyberattack on DTU: Notification of a personal data breach](https://www.dtu.dk/english/NewsArchive/2026/10/Cyberattack-on-DTU_Notification-of-a-personal-data-breach)
- [Danish university DTU breach exposes data of up to 200,000 people](https://www.bleepingcomputer.com/news/security/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people/)
- [Major Danish university hacked, 200,000 people potentially exposed](https://cybernews.com/news/dtu-university-hacked-200000-people-potentially-exposed/)
- [Data breach at Denmark's population register exposes 8.8 million people](https://www.helpnetsecurity.com/?p=386873)
- [Denmark investigates 'extremely serious' breach of national population register](https://www.computing.co.uk/news/2026/security/denmark-investigates-extremely-serious-breach-of-national-population-register)
- [Denmark CPR registry third-party access abuse, 8.8M records](https://www.rescana.com/post/denmark-cpr-registry-third-party-access-abuse-8-8m-records)
- [DTUBasen Data Breach at Technical University of Denmark Exposes Sensitive Information of 200,000 Users](https://www.rescana.com/post/dtubasen-data-breach-at-technical-university-of-denmark-dtu-exposes-sensitive-information-of-200-000-users)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3306
