Threat Insight

Recent Danish PII Exposures Increase Risk of Targeted Phishing Campaigns

Two significant incidents in Denmark have recently exposed large volumes of personally identifiable information (PII). First, the Technical University of Denmark (DTU) disclosed that attackers gained access to DTUBasen, its identity and access management platform, through compromised DTU profiles. According to DTU, information relating to approximately 200,000 current and former students, employees, guests, and partners may have been exposed. The compromised data includes names, social security numbers (CPR), email addresses, private addresses, job titles, office locations, profile photographs, and, in some cases, information relating to relatives and telephone numbers [1].

  • Insight

Separately, the Danish Central Person Register (CPR) administration disclosed a major security incident involving the misuse of a Danish company’s legitimate access to CPR data. The incident resulted in unauthorized access to information relating to approximately 8.8 million registered citizens, including names, addresses, CPR numbers, and other personal information. Authorities have revoked the company’s access, reported the incident to the Danish Data Protection Agency, and initiated an investigation with law enforcement and relevant authorities [2].

Assessment

These incidents increase the amount of Danish personal data potentially available for misuse. The exposed information could support more convincing and targeted phishing, social engineering, impersonation, and identity fraud. The DTU records are particularly relevant because contextual details such as organizational affiliation, email address, office location, and relationship information could help an attacker tailor a lure to a specific recipient.

The large-scale CPR exposure could also allow threat actors to validate or enrich information obtained from other sources. Security teams should therefore anticipate an increased risk of phishing attempts against Danish individuals and organizations that use correct personal details to establish credibility. Public reporting does not establish whether the exposed data has been acquired or operationalized by a specific threat actor, so the timing, scale, and targeting of future campaigns cannot currently be assessed.

Sikkerdigital recommends heightened attention to unexpected emails, text messages, and calls that use personal information. Recipients should not follow unexpected links. They should instead navigate independently to the organization’s official website or verify the request through its published main telephone number. Users should never disclose MitID information, one-time codes, passwords, or payment-card details. Where there is concrete suspicion that a CPR number is being misused, affected individuals can create a credit warning through borger.dk, which can make it more difficult to obtain loans or credit in their name [3].

For security operations, these recommendations support reinforced user awareness messaging, monitoring for suspicious identity and account activity, and clear escalation procedures for suspected phishing or identity misuse. Organizations should ensure that service-desk and incident-response teams can validate reports without asking users to disclose authentication secrets.

If you or your organization have concerns about the topic above or need support, please reach out to your Truesec contact for further assistance.

References

[1] Computerworld: DTU ramt af kæmpe hacker-angreb: 200.000 personers data kan være faldet i hackernes hænder
https://www.computerworld.dk/art/297044/dtu-ramt-af-kaempe-hacker-angreb-200-000-personers-data-kan-vaere-faldet-i-hackernes-haender
[2] CPR Administration: Omfattende uautoriseret adgang til borgeres CPR-oplysninger
https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger
[3] Sikkerdigital.dk: Uvedkommende har fået adgang til borgeres CPR-oplysninger: Sådan skal du forholde dig
https://www.sikkerdigital.dk/borger/digital-svindel/uvedkommende-har-faaet-adgang-til-borgeres-cpr-oplysninger-saadan-skal-du-forholde-dig

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights