Aarhus University Seal

A digital escape room: How young cyber talents learn to hack

In October, Denmark’s ten top young cyber talents will take on some of Europe’s best at the European Cybersecurity Challenge. They will break into systems, uncover hidden vulnerabilities and learn to think like hackers. It may sound malicious, but the real goal is to help protect one of the world’s most digitalised societies.

Jens Myrup Pedersen (right) coaches some of Denmark’s most talented young cybersecurity specialists. In October, the team will represent Denmark at the European Cybersecurity Challenge (ECSC) in Bochum, Germany. Photo: Mads Sejer Nielsen
Members of the Danish Cybersecurity Team train to think like hackers: finding security vulnerabilities, breaking into digital systems and learning how to protect them. Photo: Lasse Møller Badstue
Jens Myrup Pedersen, Professor of Cybersecurity at Aarhus University, coaches the Danish Cybersecurity Team, where young talents train to identify and understand vulnerabilities in digital systems. Photo: Lasse Møller Badstue

A social media profile. A picture of a burger. A name. Mr Beef.

At first glance, it looks like just another user on just another platform, posting the usual mix of jokes, memes, recipes and snippets of personal information.

But something does not quite add up.

Perhaps the user has reused a password? Perhaps one of the posts reveals a little too much? Or maybe the answer is hidden in tiny details that only the most observant will notice?

The task sounds simple: Find out who Mr Beef really is. Getting there is anything but.

Welcome to cybersecurity training.

From 12 to 16 October, the stakes will be higher when the Danish Cybersecurity Team travels to Bochum, Germany, to compete in the European Cybersecurity Challenge (ECSC). The ten Danish participants will face some of Europe’s most talented young cybersecurity specialists in challenges that require them to find vulnerabilities, break into systems and defend their own.

Before they get there, however, they will have spent countless hours practising exactly the skill that the Mr Beef challenge is designed to test: thinking like a hacker.

More than a technical discipline

Young people sit at their computers looking for clues. They click, analyse, test ideas and combine pieces of information. Not to break the law, but to understand how systems can be broken.

For Jens Myrup Pedersen, professor of cybersecurity at Aarhus University and coach of the Danish Cybersecurity Team, this way of thinking is precisely what makes cybersecurity so fascinating. It is about trying different approaches and using creativity to find solutions.

“What if you do something in a second, third or fourth way? Or in an order that nobody has tried before? Hacking isn’t just a technical discipline. Above all, it’s a creative one. It’s about trying something that nobody else has thought of before,” he says.

The Danish team consists of ten young people aged 15 to 25 who are selected through competitions and training programmes. They represent Denmark at international championships and hone their skills through realistic cybersecurity challenges.

The challenges the national team works on are far more advanced than the examples that can be solved at a glance. Participants often need to combine several techniques, work across different systems and keep track of complex connections.

“One of the reasons we have the national team is to raise the profile of cybersecurity and show young people that this is an exciting field,” says Jens Myrup Pedersen.

How do you create a cyber challenge?

A good challenge does not start with code. It starts with an idea.

“A good challenge often begins at a whiteboard, with an original idea and a good story behind it,” explains Jens Myrup Pedersen.

The story matters. If the challenge feels like a world you can explore, solving it becomes much more engaging.

“We create challenges that make you want to explore. It shouldn’t just be technical. It should be an experience,” he says.

The setting might be a social media platform, an online shop or another digital system. But there is a catch: it has deliberately been built with flaws.

“We actually build vulnerabilities into the website or systems used in the competition. The participants then have to find those vulnerabilities and exploit them,” says Jens Myrup Pedersen.

In the most difficult challenges, several pieces have to fall into place at once.

“If you want to make it difficult, there should be several pieces of the puzzle that have to come together, so you need to use several tools and exploit several vulnerabilities at the same time,” he explains.

This is where the difference in skill level becomes clear. A beginner’s challenge might involve spotting a few individual clues. At national-team level, participants work with tasks involving multiple layers of interconnected systems, where finding the solution requires experience, creativity and persistence.

Only the very best reach that level.

Who is Mr Beef?

Back to the fictional social media platform.

The people behind the Danish Cybersecurity Championships have built an entire network of users, posts and relationships. It looks like a real platform, but it is actually a carefully constructed challenge.

Mr Beef is one of its users. He posts pictures. Leaves comments. Likes other people’s posts. At first glance, none of it seems particularly important. To a hacker, however, every detail could be a clue.

A post might reveal a habit. A like could reveal an interest. A photograph might reveal something in the background.

“A user might post a photo where you can just make out a Post-it note with a username and password on it,” says Jens Myrup Pedersen.

Other clues can be more subtle.

“You might be able to combine different clues and eventually work out a user’s password because they’ve liked a post suggesting that you create passwords from the name of your pet and your year of birth, or something along those lines,” he explains.

Then the detective work begins. Find the pet’s name. Find the year of birth. Test different combinations. Gradually, the pieces come together.

“By combining all that information, you can find things that ultimately allow you to get into the system. It’s like an escape room, with small clues that come together and make you feel as though you’re getting closer and closer to the solution.”

The challenges are not arbitrary. They reflect real-world problems.

“We’re not training people to become malicious hackers. We’re teaching them to understand vulnerabilities so they don’t build the same flaws into their own systems, and to find vulnerabilities quickly so they can close them before malicious hackers discover them,” says Jens Myrup Pedersen.

These kinds of mistakes are everywhere: reused passwords, too much personal information on social media, systems that were not designed with security in mind from the outset. They are not necessarily sophisticated hacks. Often, they are simply unintended human errors.

Mr Beef is a simplified version of the challenges participants encounter. At national-team level, the tasks are far more complex. Participants may have to combine several vulnerabilities, work across different systems and complete a sequence of steps in precisely the right order before they can move forward.

When 400 young people hack each other

Cybersecurity has a reputation for being difficult and highly specialised.

The Danish Cybersecurity Team is trying to change that.

“We want to make it more accessible to everyone, including people who might only have half an hour in a working day once a month to devote to cybersecurity,” says Jens Myrup Pedersen.

“We want to reach everyone, not just the geekiest boys, so we can bring more diversity into the field.”

That is also why the challenges can involve subjects such as social media, data and privacy.

“If you open it up and include data, the way we use social media and the protection of privacy, suddenly a much broader group of people finds it interesting. Cybersecurity is incredibly important to society as a whole,” he explains.

At the European championship, the pace changes. From 12 to 16 October, more than 400 participants from 42 countries will gather in Bochum, Germany, for the ECSC.

“At the European championships, there are both challenges and attack-defence days, where 400 young people are sitting there hacking each other back and forth. It’s fantastic,” says Jens Myrup Pedersen.

The teams have to attack and defend at the same time. They must protect their own systems while trying to break into those of their opponents.

Cybersecurity in action.

AI: A new ally – and adversary

Back to Mr Beef.

Now imagine that you did not have to find the clues yourself. Imagine asking an artificial intelligence system to do it for you. It could analyse posts. Identify patterns in behaviour. Guess likely passwords. All within seconds.

This is not science fiction. It is already happening.

In just a few years, artificial intelligence has significantly changed cybersecurity.

“AI is hugely important in this world. It changes both attack and defence,” says Jens Myrup Pedersen.

Phishing emails, for example, used to be relatively easy to spot because of poor language and generic wording. Today, AI can produce grammatically correct messages tailored to an individual recipient.

An attacker can use AI to analyse your social media activity, craft targeted attacks and write personalised phishing emails. AI can also imitate voices or people and intelligently test thousands of password combinations.

“In phishing attacks, for example, AI can be extremely good at writing convincing emails targeted at individual people, making them appear very credible,” says Jens Myrup Pedersen.

Tasks that once required considerable time and expertise can now be carried out faster and with fewer resources. A single attacker could potentially target thousands of people with tailored attacks, making cyberattacks faster, cheaper and more precise. By analysing vast quantities of code or network traffic, algorithms can also identify weaknesses far faster than a human can.

“In my view, it has clearly made things easier for attackers,” says Jens Myrup Pedersen.

At the same time, defending systems becomes harder.

“Cybersecurity is an asymmetric contest. On the defensive side, we have to win every single time. The attackers only need to get through once to win. The defences we build have to work every time,” he explains.

AI amplifies that imbalance.

Why it matters

Cybersecurity has become essential to the functioning of society, and the demand for people who understand it is growing.

“We really need talent,” says Jens Myrup Pedersen.

But that requires more people to want to get involved.

“Without elements like gamification, rewards and the escape-room experience, many people will immediately think, ‘That’s too difficult. I can’t do that.’ Those elements can make a real difference,” he explains.

Turning cybersecurity into an experience changes the way people approach it.

When participants try to uncover the identity of Mr Beef – or tackle the far more complex challenges they encounter at national-team level – they are not simply solving a puzzle.

They learn how to think. How to ask questions. How to recognise patterns. How to stay curious. And, perhaps most importantly, that digital systems are never perfect.

Understanding that is what helps them build better ones.

The Danish Cybersecurity Team is therefore also a way of developing talent in a field where demand for expertise is growing – and where society increasingly depends on people who understand how to keep digital systems secure.

Because ultimately, this is not about hacking.

It is about understanding – and protecting.

Facts: The Danish Cybersecurity Team

The Danish Cybersecurity Team consists of ten young people aged 15 to 25 who are selected through competitions and training programmes. They train to find and exploit vulnerabilities in digital systems in order to learn how cyberattacks can be detected and prevented.

The team represents Denmark at the European Cybersecurity Challenge (ECSC), the European championship in cybersecurity for young people. In 2026, the competition takes place in Bochum, Germany, from 12 to 16 October, bringing together more than 400 young cyber talents from 42 countries.

Participants compete across a range of cybersecurity disciplines. Among other things, they analyse vulnerable systems and take part in attack-defence challenges, in which they must attack their opponents’ systems while defending their own.

The aim of the Danish Cybersecurity Team is both to develop some of Denmark’s most talented young cybersecurity specialists and to encourage wider interest in the field at a time when demand for these skills is growing. The team is funded by the Danish Industry Foundation.

Contact

Professor Jens Myrup Pedersen
Department of Electrical and Computer Engineering, Aarhus University
Mail: jensmyrup@ece.au.dk
Tel.: +4521847931

Jesper Bruun
Journalist, Aarhus University
Mail: bruun@au.dk
Tel.: +4542404140