
Denmark confirms unauthorized access to 8.8 million records
Someone used a private company's legitimate access to the Danish civil registry. The digitalization minister admits the security was not good enough.
Someone without authorization searched Denmark's civil registry and was able to see data on about 8.8 million people, the Ministry of Research, Education and Digitalization said on Oct. 5. The data are names, home addresses and CPR numbers, the personal ID that each resident uses with the government, banks and public health services.
It was not a software flaw. The CPR administration, which runs the registry, detected "irregular conduct" on Friday, Oct. 2, and says those responsible abused the legitimate access a Danish company has to look up data in the system. The activity took place during September. The company has not been named.
The registry includes people who have died and people who emigrated. Those with name and address protection were left out of the access, according to the ministry.
Minister Christina Egelund called the case a "very serious incident." The Copenhagen Post quotes her saying the security measures around that company's access were not good enough. The outlet puts the activity at about ten days; the ministry statement this newsroom read does not give that duration.
The CPR administration cut off the company's access and notified Datatilsynet, Denmark's data protection authority. Police are investigating with other authorities.
Jens Myrup Pedersen, a cybersecurity specialist at Aarhus University, warned in The Copenhagen Post that the data could make *phishing* more convincing: scams by message or phone call that pose as an authority to get passwords. The Danish government, for its part, says people should never hand over passwords or confidential data in a phone call, even if the caller already knows their details. Its help line is the Cyberhotline, +45 33 37 00 37.
There is no CVE: the case does not exploit a published vulnerability. Who made the queries and why has not been confirmed, and no source links this case to the Oct. 2 attack on the Technical University of Denmark, which also exposed CPR numbers.



