8.8 Million Affected in Denmark’s Central Person Registry Data Breach – Latest Update
Denmark’s Central Person Registration System Experiences Major Data Breach Affecting 8.8 Million Individuals
Overview of the Breach
The Danish national civil registration system, known as the Central Person Registration (CPR), experienced a significant data breach impacting approximately 8.8 million individuals. The CPR system, established in 1968, maintains records for about 11 million people, including residents, emigrants, and deceased individuals.
Discovery and Response
The breach was discovered on Friday when the organization identified unauthorized access to personal data. Attackers exploited a Danish company’s authorized access to the system, leveraging legal provisions that allow private entities to request individual-level information under the country’s Data Protection Regulation and Data Protection Act. The compromised data included names, addresses, and CPR numbers, which function as national identification identifiers.
Impact and Mitigation
The breach did not affect individuals who had opted out of the system. Upon detection, the CPR system immediately revoked the private company’s access, reported the incident to the Danish Data Protection Agency, and initiated an investigation in collaboration with law enforcement and relevant authorities. The organization stated it would review and enhance its security protocols to prevent future incidents.
Implications and Investigations
The breach highlights vulnerabilities in access controls and the risks associated with third-party data sharing under legal frameworks. Authorities are investigating the extent of the data exfiltration and potential misuse of the stolen information. No specific threat actor has been identified, but the incident underscores the importance of stringent monitoring and oversight of data access permissions.
Current Status and Future Measures
The CPR system remains operational, and affected individuals are being notified through official channels. The incident has prompted discussions about revising data protection policies to better safeguard sensitive information in public registries.
Authorities are investigating the extent of the data exfiltration and potential misuse of the stolen information.
Conclusion
The incident underscores the critical need for robust data security measures and continuous evaluation of third-party access protocols to protect sensitive personal information.
