Interestana
Home/News/Danish CPR Data for 8.8 Million Accessed via Company Account
The Hacker News••2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Danish CPR Data for 8.8 Million Accessed via Company Account

Danish CPR Data for 8.8 Million Accessed via Company Account

Unauthorized actors gained access to the names, addresses, and personal identification numbers of approximately 8.8 million individuals in Denmark's national population register, the country's digitalization ministry announced on October 5. The breach occurred through the exploitation of a private Danish company's legitimate access privileges to query records within the Central Person Register (CPR). This incident impacts both living and deceased residents of Denmark, as the CPR contains comprehensive demographic information. The ministry has issued guidance to citizens, advising them to remain vigilant and take necessary precautions to protect their personal information. The specific private company whose account was compromised has not been publicly identified by the ministry, nor has the exact timeframe during which the unauthorized access took place. However, the ministry confirmed that the attackers utilized the company's lawful access to the CPR system to extract the sensitive data. The Central Person Register (CPR) is a foundational element of Danish public administration, used for a wide array of services including healthcare, taxation, and social benefits. Its integrity is paramount for the functioning of the state and the security of its citizens. The Danish Data Protection Agency (Datatilsynet) has been notified and is expected to launch an investigation into the incident. This breach raises significant concerns about the security protocols of third-party companies that are granted access to sensitive government databases. The ministry stated that it is working closely with relevant authorities and the compromised company to understand the full scope of the breach and to implement enhanced security measures to prevent future occurrences. The investigation will likely focus on how the attackers gained unauthorized entry into the company's system and how they managed to exfiltrate such a large volume of personal data. The Danish government has emphasized its commitment to transparency and will provide further updates as the investigation progresses. Citizens are being advised to monitor their financial accounts and be wary of any unsolicited communications that request personal information. The scale of the data compromised, affecting nearly all of Denmark's population, underscores the critical need for robust cybersecurity practices across all entities handling personal data, especially those with access to national registers. The ministry has not yet detailed specific remediation steps for affected individuals beyond general advice for vigilance.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next