8.8 Million Affected by Denmark’s Central Person Register Data Breach
8.8 million people were impacted by a data breach at Denmark’s Central Person Register, exposing sensitive personal information.
Overview of the Register
Danmark’s Central Person Register, established in 1968, serves as the nation’s civil registration system, housing data on approximately 11 million individuals, including residents, emigrants, and deceased persons.
Details of the Breach
A recent cybersecurity incident revealed that malicious actors exploited a Danish company’s authorized access to the system to extract personal information. The breach involved names, addresses, and CPR numbers—equivalent to Social Security numbers—for roughly 8.8 million people. The incident did not involve individuals who had opted out of the system.
Legal Framework and Access
Under Danish legal frameworks, private entities with legitimate needs may access the register to obtain details about specific individuals, either through data protection regulations or the Data Protection Act.
Response and Investigation
The breach was identified on Friday, with investigators determining that unauthorized parties accessed the data. Upon discovery, administrators revoked the private company’s access, reported the breach to the Danish Data Protection Agency, and initiated a collaborative investigation with law enforcement and other relevant authorities.
Implications and Security Concerns
The organization stated it would conduct a comprehensive review of its security protocols to enhance safeguards against future threats. The breach highlights vulnerabilities in third-party access controls and underscores the risks associated with lawful data access mechanisms.
The breach highlights vulnerabilities in third-party access controls and underscores the risks associated with lawful data access mechanisms.
Ongoing Investigation and Future Steps
No further details about the attackers, methods, or affected companies were disclosed at the time of reporting. The incident has prompted renewed scrutiny of data protection measures for critical national registries, emphasizing the need for stringent access management and continuous monitoring of external partnerships. Authorities are expected to release additional updates as the investigation progresses.
