GBHackers

Denmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records


Denmark has confirmed a serious cybersecurity incident involving unauthorized access to personal information in its Central Person Register (CPR), affecting about 8.8 million registered individuals.

The exposed records include names, residential addresses, CPR numbers, and potentially other information held in the country’s national civil registration system.

The breach’s impact exceeds Denmark’s current population because the CPR database also contains records for deceased individuals and former residents who have left the country.

However, authorities have noted that individuals protected by name-and-address confidentiality settings were not included in the exposed dataset.

Denmark Confirms Major Security Incident

The CPR administration stated that the intrusion did not result from a direct compromise of the national registry’s public-facing infrastructure. Instead, unauthorized actors reportedly exploited a Danish company’s legitimate ability to search the CPR system.

This incident highlights a major failure in third-party access: a trusted organization with authorized access became the means by which a large volume of records was retrieved.

The company’s access has since been suspended while investigators determine how the access was misused and whether credentials, systems, or internal processes were compromised.

Authorities reportedly detected irregular activity on October 2, which led them to establish that unauthorized searches had occurred in September. Authorities have not publicly identified the individuals responsible, and officials have not disclosed the specific technical method used to access the company’s authorized connection.

While Danish authorities have not confirmed whether the data was exfiltrated, sold, or used for fraud, the combination of full names, physical addresses, and CPR numbers poses a significant downstream risk.

A CPR number is a central personal identifier used across both public-sector and private services in Denmark. Threat actors could utilize authentic identity data to carry out phishing, vishing, smishing, account recovery, impersonation, or social engineering attempts that appear credible.

An attacker with knowledge of a target’s name, address, and CPR number may be able to bypass basic identity verification checks or impersonate trusted institutions more convincingly.

Security researchers warn that this information could enable highly tailored fraudulent messages impersonating government agencies, banks, healthcare providers, or delivery services.

The CPR administration has reported the incident to Denmark’s Data Protection Authority, Datatilsynet, and police are investigating in coordination with relevant government agencies. Officials are also working with specialists to map the full sequence of events and determine the extent of the breach.

Minister of Research, Education, and Digitalization Christina Egelund described this event as a “deeply serious incident.” She stated that Parliament’s Business and Digitalization Committee has been informed and has ordered a comprehensive security review of the CPR system.

Danish authorities are urging residents to treat unsolicited communications with heightened suspicion, even when a caller or sender appears to know accurate personal details.

Citizens should never disclose passwords, authentication codes, banking information, or other confidential data in response to unexpected calls, emails, or messages.

Affected individuals can seek guidance through Denmark’s Sikkerdigital portal and the Cyberhotline for digital security, which has extended its operating hours following the incident.

This event underscores a critical lesson for public-sector identity systems: authorized access must be continuously monitored, tightly scoped, and quickly revocable to limit the impact of third-party compromises.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link