Denmark Data Breach Impacts 8.8 Million in Central Person Register

www.news4hackers.com-denmark-data-breach-impacts-8-8-million-in-central-person-register-denmark-data-breach-impacts-8-8-million-in-central-person-register

Denmark’s Central Person Register (CPR) suffered a major data breach impacting 8.8 million individuals through unauthorized access by a private entity.

Overview of the Data Breach

Denmark’s national civil registration system, known as the Central Person Register (CPR), experienced a significant data breach affecting approximately 8.8 million individuals. The incident involved unauthorized access to the system through a private entity’s legally permitted entry, resulting in the extraction of personal data.

The Central Person Register (CPR)

The CPR, established in 1968, maintains records for around 11 million people, including residents, emigrants, and deceased individuals. Under Danish law, private companies with valid reasons can access the CPR to retrieve information on specific individuals, either through data protection regulations or statutory requirements.

How the Breach Occurred

The breach was detected on Friday, with investigators determining that hackers exploited a third-party company’s authorized access to the system. The compromised data included names, addresses, and CPR numbers, which function as national identification codes akin to Social Security numbers.

Data Compromised

The breach did not impact individuals who had opted out of the system. Following the discovery, the CPR immediately revoked the private company’s access, reported the incident to the Danish Data Protection Agency, and initiated a collaborative investigation with law enforcement and regulatory bodies.

Response and Investigation

The organization also announced plans to reassess its security protocols to strengthen protections against future incidents. The breach highlights vulnerabilities in third-party access controls and the risks associated with lawful data access mechanisms. While no specific threat actor has been identified, the incident underscores the importance of stringent oversight for entities granted privileged system access.

Implications and Lessons Learned

The CPR’s response included immediate termination of the compromised access point, regulatory notifications, and a review of security measures to prevent similar occurrences. No financial losses or additional details about the breach’s origin have been disclosed publicly. The incident adds to a series of recent data breaches impacting healthcare providers, government agencies, and private organizations globally, emphasizing the ongoing challenges in securing sensitive personal information.



About Author

en_USEnglish