Hackers exploited legitimate access to Denmark’s national population registry, exposing names, addresses and personal identification numbers connected to about 8.8 million registered people, as authorities investigate what officials called an extremely serious breach.
The affected database is the Central Person Register, or CPR, which contains information on current residents as well as people who have emigrated or died. Denmark has roughly six million residents, while the CPR holds records on about 11 million people, explaining why the number affected exceeds the country’s population. Initial findings indicate that attackers used access belonging to a Danish company authorized to search the registry, rather than breaking directly into the government system.
Irregular activity was detected on October 2, although investigators believe the unauthorized access may have begun in September. Officials said the compromised information included CPR numbers, Denmark’s equivalent of national identification or Social Security numbers. The CPR administration has revoked the abused access, notified the Danish Data Protection Authority and referred the incident for police investigation.
Authorities have not identified the attackers and say they are still determining the breach’s full scope, while a broader security review is underway.