Compromised Credentials Expose Personal Data of Up to 200,000 Users at Denmark’s Technical University (DTU)
What Happened – Attackers used stolen credentials to log into DTU’s identity and access management platform (DTUBasen) and downloaded extensive user records spanning two decades. The breach potentially includes civil registration numbers (CPR), names, addresses, photos, employment details, and next‑of‑kin information for current and former staff, students, guests, and partners.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk when privileged IAM accounts are not protected by multi‑factor authentication and continuous credential‑use monitoring.
- Highlights the need for auditable evidence that access rights are reviewed, revoked promptly, and that anomalous log‑ins are detected in real time.
- Directly tests the control objective of Identity & Access Management that underpins many frameworks (e.g., NIST CSF 2.0, ISO 27001) – a single strong IAM control supports compliance across the board.
Who Is Affected – Higher education institutions, research organizations, and any entity that maintains large IAM directories with personal identifiers.
Recommended Actions
- Enforce MFA for all privileged and service‑account logins and rotate credentials immediately.
- Implement continuous monitoring of IAM activity, generate immutable logs, and retain them for audit‑ready evidence.
- Conduct a rapid access‑rights review, revoke unused accounts, and notify affected individuals per data‑protection regulations.
Source: BleepingComputer
Technical Notes – Attack vector: stolen credentials (likely obtained via phishing or credential‑stuffing). No public vulnerability (CVE) disclosed; the breach stems from credential compromise rather than a software flaw. Exfiltrated data includes CPR numbers, full names, addresses, photos, employment details, and next‑of‑kin contacts. Source: same as above