8.8 Million Affected in Denmark’s Central Person Register Data Breach
Denmark’s Central Person Registration (CPR) system, established in 1968, serves as the nation’s civil registration database, housing records for approximately 11 million individuals, including current residents, emigrants, and deceased persons.
Overview of the CPR System
The CPR system, established in 1968, serves as Denmark’s civil registration database, housing records for approximately 11 million individuals, including current residents, emigrants, and deceased persons. Under Danish legislation, private entities with legitimate reasons can access the CPR to obtain information about specific individuals, either through data protection regulations or statutory requirements.
Breach Details
A recent cybersecurity incident revealed that attackers exploited a Danish company’s authorized access to the system to extract sensitive personal data. The breach was identified on Friday, with investigators determining that cybercriminals accessed the names, addresses, and CPR numbers—equivalent to Social Security numbers—of roughly 8.8 million people. The incident did not involve individuals who had previously opted out of the system.
Response by Authorities
Upon discovery, the CPR authority immediately revoked the private company’s access privileges, reported the breach to the Danish Data Protection Agency, and initiated a joint investigation with law enforcement and other relevant agencies. The organization also announced plans to reassess its security protocols and implement enhanced safeguards to prevent future compromises.
Vulnerabilities Highlighted
The breach highlights vulnerabilities in third-party access controls and underscores the risks associated with lawful data access mechanisms. Authorities are currently analyzing the scope of the compromise, including the methods used by attackers to exfiltrate data and the potential for further exploitation.
Investigation Status
No details have been released regarding the specific company involved or the technical vectors employed in the attack. The incident follows a series of high-profile data breaches affecting healthcare providers, government agencies, and private enterprises globally, emphasizing the persistent challenges of securing sensitive information in an increasingly interconnected digital landscape.
