Denmark CPR Breach Exposes Data of 8.8 Million People

Attackers abused a private firm's lawful lookup rights to pull names, addresses and CPR numbers of 8.8 million people from Denmark's Central Person Register.
Table of Contents
    Add a header to begin generating the table of contents

    Denmark’s digitalization ministry announced that attackers pulled names, addresses and personal identification numbers for about 8.8 million people from the Central Person Register, the national database known as the CPR. The access ran through a small private company that holds a legitimate right to look up register records, and police have opened an investigation.

    How Attackers Turned a Private Company’s CPR Access Into a Mass Data Pull

    The ministry said the intruders did not break into the register directly. They abused the lookup rights granted to a small private Danish company, and the company’s access has since been blocked. According to Datatilsynet, the Danish Data Protection Agency, the activity consisted of a very large number of automated lookups. The agency said the requests appeared designed to identify valid CPR numbers first, then extract the data attached to each entry.

    That pattern resembles brute-force enumeration: guess or generate candidate numbers, keep the ones that return a record, and harvest the associated details. Datatilsynet described the 8.8 million figure as “allegedly retrieved” and said it has not yet assessed the case itself. The ministry has also said the number is not final.

    Roughly 80 Percent of the Register Reached Over About 10 Days

    The register holds records on about 11 million people, covering residents, emigrants and the deceased, and it has recorded everyone living or formerly living in Denmark since 1968. The 8.8 million affected records therefore represent roughly 80 percent of the database. Living and dead individuals are both included.

    The abnormal lookup activity ran for about 10 days in September. A register administration employee noticed unusual activity on October 2. Over the following weekend the administration worked out how many records were affected and notified Datatilsynet on October 4. The ministry and the agency went public on October 5.

    People who have name-and-address protection were not affected as far as names and addresses go. It remains unclear whether their CPR numbers were reached, according to reporting on the ministry’s statement.

    What Is Still Unknown About the CPR Attackers and the Company’s Compromise

    Authorities have not named a threat actor. Several basic questions are open: how the private company was compromised or its access otherwise taken over, whether the retrieved data has been retained or used, and who is behind the activity. Datatilsynet has said it has not yet assessed the case, so no finding has been made about the company whose rights were abused.

    The incident differs from the typical register breach in one respect. The register itself appears to have functioned as designed, answering lookups from an authorized party. The failure sits in how a third party’s legitimate access could be driven at that volume for about 10 days before an employee flagged it.

    Fraud and Social-Engineering Risk Tied to the CPR Number

    The CPR number is Denmark’s equivalent of a social security number, and it is widely used to confirm identity. Exposure of the number alongside a name and address gives criminals the building blocks for phone and email fraud in which the caller already knows the target’s identifier. The government’s guidance reflects that risk: the public has been told never to hand over passwords or confidential data to callers or emailers, even when the contact already knows a person’s CPR number.

    A leaked CPR number cannot be reissued the way a password can. It stays attached to a person for life, so the exposure carries a longer tail than a typical credential leak.

    Government Response: Blocked Access, Added Safeguards and a Public Hotline

    Beyond cutting off the company, the authorities added extra security measures to the CPR. Police opened an investigation, and Digitalization Minister Christina Egelund informed Parliament’s Business and Digitalization Committee. The government set up a cyber hotline and published guidance on sikkerdigital.dk for people worried about their exposure.

    Detection here depended on a register administration employee noticing unusual activity on October 2, roughly 10 days after the lookups began, and not on an automated control. Datatilsynet has yet to complete its assessment of the case, and the government has not said whether it will change how private companies obtain lookup rights.

    Related Posts