8.8 Million Impacted by Denmark’s Central Person Register Data Breach
8.8 million individuals were impacted by a data breach at Denmark’s Central Person Registration System, exposing sensitive personal information including names, addresses, and CPR numbers.
Overview of the Data Breach
Denmark’s Central Person Registration System, established in 1968, serves as the nation’s civil registration database, housing information on approximately 11 million individuals, including residents, emigrants, and deceased persons. A recent cybersecurity incident revealed that unauthorized actors exploited a Danish company’s authorized access to the system to extract sensitive personal data.
Details of the Central Person Registration System
Under Danish legal frameworks, private entities with legitimate reasons may access the registry to obtain details about specific individuals, or they may request information through the country’s Data Protection Regulation and Data Protection Act. The breach was identified on Friday, with investigators determining that attackers accessed the system over the weekend. The compromised data includes names, addresses, and CPR numbers—Denmark’s equivalent of Social Security numbers—for roughly 8.8 million individuals.
Scope and Impact of the Breach
Notably, the breach does not affect those who had opted out of the registry. Upon discovering the incident, the Central Person Registration System immediately revoked the private company’s access privileges, informed the Danish Data Protection Agency, and initiated a collaborative investigation with law enforcement and relevant authorities.
Response and Mitigation Efforts
The organization has also announced plans to reassess its security protocols and implement enhanced safeguards to prevent future compromises. Authorities are working to determine the full scope of the breach and identify potential measures to mitigate risks for affected individuals.
The breach highlights vulnerabilities in systems granting third-party access to critical national databases, underscoring the need for stringent oversight and continuous monitoring of data access mechanisms.
