8.8 Million Affected in Major Denmark Data Breach at Central Person Register

www.news4hackers.com-8-8-million-affected-in-major-denmark-data-breach-at-central-person-register-8-8-million-affected-in-major-denmark-data-breach-at-central-person-register

8.8 million individuals were affected by a data breach at Denmark’s Central Person Register (CPR), a national civil registration system.

Overview of the Breach

Denmark’s Central Person Register (CPR), a national civil registration system established in 1968, experienced a significant data breach affecting approximately 8.8 million individuals. The system, which maintains records for about 11 million people—including residents, emigrants, and deceased individuals—was compromised through unauthorized access to a Danish company’s lawful entitlement to retrieve personal data.

Details of the Breach

Under Danish legislation, private entities with valid justifications may access the CPR to obtain information on specific individuals. Additionally, companies can request data under the country’s Data Protection Regulation and Data Protection Act. The breach was identified on Friday when the CPR system detected anomalous activity. Further investigation over the weekend revealed that attackers exfiltrated personal details, including names, addresses, and CPR numbers, which function as national identification identifiers similar to Social Security numbers.

Response and Investigation

The incident did not affect individuals who had previously opted out of the system’s data sharing protocols. Upon discovery, the CPR immediately revoked the private company’s access privileges, reported the breach to the Danish Data Protection Agency, and initiated a collaborative investigation with law enforcement and relevant regulatory bodies. The organization also announced plans to reassess its security frameworks and implement enhanced safeguards to prevent future incidents.

Implications and Lessons Learned

The breach highlights vulnerabilities in third-party access controls and underscores the risks associated with lawful data access mechanisms. The CPR’s response included immediate containment measures and a commitment to strengthening protective measures. No further details about the attackers, the method of exploitation, or the specific company involved were disclosed at the time of reporting. The incident adds to a growing list of high-profile data breaches affecting critical infrastructure and government systems, emphasizing the need for continuous monitoring and adaptive security strategies.



About Author

en_USEnglish