deniz.in

Markets

Weather

Loading weather

· via TechCrunch

Denmark confirms CPR breach with records of about 8 million people stolen

Denmark has confirmed that hackers copied data on roughly 8 million people from its Central Person Register by exploiting a private company's lawful access to the system.

Denmark confirms CPR breach with records of about 8 million people stolen

What happened

Denmark's government has confirmed that its central database of citizen records was breached and that a large portion of its contents was stolen. According to TechCrunch, the incident affects roughly 8 million citizens and residents, including Danes living abroad and people who have died but whose records are still held in the system.

Danish minister Christina Egelund described the compromise of the Central Person Register (CPR) as a "serious incident" and confirmed that the stolen data includes names, addresses, Danish social security numbers and other information.

TechCrunch reports that the intrusion took place in September but was only discovered on October 2, meaning attackers had access to the data for some time before anyone noticed.

What the CPR actually is

The CPR is not a niche government system. It is the register that stores the government-issued identity number Danes rely on to pay taxes and to access public services, making it one of the most sensitive datasets the Danish state holds.

That sensitivity is amplified by the register's reach. Denmark's current population is around 6 million, but the database contains records on about 11 million people, and some of the data goes back decades, according to TechCrunch. The affected figure of 8 million exceeds the country's living population precisely because the register spans current residents, emigrants and the deceased.

How the attackers got in

The breach did not, apparently, involve a direct assault on government infrastructure. In its statement, the government said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system."

Certain companies in Denmark are permitted to query the CPR to verify people's information against government records, and the attackers appear to have exploited one of those legitimate channels rather than defeating the state's own defenses. Authorities did not name the company involved, nor would they say who they believe is behind the attack.

A record-setting incident

TechCrunch reports that the breach is thought to be the largest in Denmark's history. It also fits a broader pattern of attacks and exposures targeting national identity databases: a 2016 breach affected millions of Turkish citizens, and India's Aadhaar system has suffered repeated exposures of national ID data over the years.

Why it matters

The incident highlights two structural problems that extend well beyond Denmark.

First, identity data is the hardest kind to remediate. A stolen password can be rotated; a national identity number tied to taxation and public services generally cannot. With names, addresses and CPR numbers in attackers' hands, the realistic risk is long-term: more convincing phishing, impersonation, and fraud attempts that leverage authoritative government data. The fact that the dataset includes deceased individuals also creates openings for estate-related and historical impersonation scams.

Second, the attack vector matters as much as the outcome. If attackers reached a national register through a private company's authorized access, then the effective security perimeter of the CPR is not the government's own systems but every third party allowed to query them. Expect pressure on Danish authorities to explain how that access was granted, whether it was adequately logged and monitored, and why the misuse apparently went undetected for weeks before discovery on October 2.

For other countries running comparable population registers, the breach is a case study in how trusted intermediaries can become the weakest link — and in the cost of centralizing lifetime identity data in a single system that, once drained, cannot simply be re-secured.

  • #data-breach
  • #denmark
  • #security
  • #privacy
  • #government-data

Related posts