Hacker attack on DTU: Outdated IT systems make universities vulnerable
More than 200,000 people may be affected by a hacker attack on the Technical University of Denmark (DTU). A cybersecurity professor warns that old IT systems make Danish universities easy targets.

Cybersecurity expert: Universities pay the price for outdated IT
More than 200,000 people may be affected after hackers breached the Technical University of Denmark's (DTU) user database and extracted a large amount of data. The Copenhagen Post reports that the attack has now focused attention on a broader security problem at Danish universities.
Jens Myrup Pedersen, professor of cybersecurity at Aarhus University, warns that the combination of large quantities of personal data and outdated IT infrastructure makes universities particularly attractive targets for cybercriminals.
"Universities possess a very large amount of personal data," Pedersen told Ritzau. "And it is my impression that several universities have some older systems that probably do not have the security standard one can expect in 2026."
Pedersen emphasises that he cannot comment specifically on the quality of DTU's IT security. However, he points to two central questions that the attack raises: which accounts have had access to personal data, and how well are these accounts protected. A third question is whether the universities' systems are even capable of registering when unusually large amounts of data are extracted, and whether they can trigger an alarm before the damage becomes too extensive.
Threat level assessed as "very high"
DTU is not an isolated case. Danish universities have been targets of hackers several times in recent years. An assessment from 2025 made by the Agency for Societal Security placed the cybercrime threat against Danish universities in the "very high" category.
According to experts, the reason is that universities combine large personal registers with complex IT environments that are used daily by thousands of students, researchers and staff – a broad attack surface that is difficult to protect fully.
CPR numbers and addresses may be compromised
DTU stated on Friday that unauthorised parties gained access to multiple user accounts and used them to penetrate the university's user database. According to DTU, the extracted information may include CPR numbers, home addresses and telephone numbers.
The university has not yet determined precisely which information has been stolen, or how many people are directly affected.
The case has been reported to the Data Protection Authority. The National Special Crime Unit (NSK) is in contact with DTU about the incident. It has not been disclosed who is suspected of being behind the attack.
DTU has not commented further on when victims will be directly informed, or what steps the university will take to strengthen security going forward.
Source: The Copenhagen Post