CISOOnline

Denmark’s national ID system breach exposes personal data of 8.8M

Denmark is reviewing security controls around its national citizen registry after unauthorized parties exploited a company’s access credentials to harvest records on approximately 8.8 million people over a 10-day period. The breach covers people living in Denmark as well as individuals who have died or moved abroad, while people with protected names and addresses were not affected.

The unauthorized activity took place for about 10 days in September and was discovered on October 2 after CPR administrators noticed unusual activity. Authorities subsequently found that more than 14 million searches had been made through the company’s account, with about 8.8 million returning records.

The affected company has since been cut off from the CPR system, while Denmark’s National Special Crime Unit is investigating. Authorities have not identified those responsible, but officials have warned that the exposed CPR numbers could enable fraud and identity-related abuse.



Source link