Decoding the world of cybersecurity

Denmark breach exposes data on 8.8 million people

Denmark is investigating unauthorised access to its central population register after a private company’s legitimate connection was abused to obtain personal data relating to around 8.8 million registered people.

Denmark breach exposes data on 8.8 million people
Summary
  • A Danish company’s legitimate CPR access was abused to retrieve data relating to around 8.8 million registered people.
  • The exposed information includes names, addresses, CPR numbers and other population register data.
  • The company’s access has been stopped while police and data protection authorities investigate.

Denmark is investigating a major security incident affecting its central population register after unauthorised users abused a private company’s legitimate access to retrieve personal information relating to around 8.8 million registered people.

The Central Person Register, known as CPR, said the accessed information included names, addresses, CPR identification numbers and other data held within the system. Its review found that names and addresses belonging to people registered with name and address protection were not included in the unauthorised access.

Rather than compromising the central register through an unauthorised external connection, the perpetrators used access already granted to a Danish company. CPR administrators have stopped that organisation’s connection while specialists and public authorities reconstruct what happened, and the incident has been reported to Denmark’s data protection authority and police.

Authorities have not publicly identified the company, established how its authorised access came to be abused or said how long the activity continued. Those questions will determine whether investigators are dealing with compromised credentials, a wider breach of the supplier’s systems or another weakness in the access chain.

Because the requests came through an organisation already trusted to query CPR, controls designed primarily to reject unknown external users would not necessarily have prevented the extraction. The incident instead puts the emphasis on how much information an authorised third party can retrieve, how that activity is monitored and whether unusual search volumes can be detected while the connection itself remains valid.

Dray Agha, Senior Manager, Tactical Response at Huntress, said: “A compromised account at a single supplier can bypass an organisation’s core security controls and turn a legitimate connection into a massive data exposure.”

CPR sits at the centre of Danish public administration and assigns residents a personal identification number used across interactions with government and other organisations. That makes the exposed information different from an ordinary account credential because a national identifier cannot simply be rotated in the way an organisation can reset a password after a breach.

Jamie Akhtar, CEO and co-founder of CyberSmart, said the incident showed how third-party access could become a route to sensitive information, with names, addresses and identification numbers potentially making later impersonation attempts or fraudulent communications more convincing.

Although passwords were not identified in the CPR disclosure, identity information can remain useful long after an incident has closed. Historical addresses, family relationships and persistent identifiers can be combined with material from other breaches or public sources to build more detailed profiles of individuals.

Simon Pamplin, CTO at Certes, described that permanence as a defining feature of the incident. “These are not credentials that can be rotated or reset. For the individuals affected, the exposure is indefinite.”

Pamplin also argued that a dataset covering such a large proportion of a national population could attract interest beyond ordinary fraud, including from intelligence actors. Danish authorities have not attributed the incident to a state, criminal group or other actor, however, and no motive has been established publicly.

The scale of the exposure also places the security of delegated access under scrutiny. Central databases frequently have to serve government departments, service providers and other authorised organisations, so removing all external access is rarely practical. The security question becomes how narrowly those privileges can be defined and whether a legitimate account can retrieve data at a scale inconsistent with its normal purpose.

Continuous monitoring can provide one layer of control where prevention alone cannot distinguish an ordinary authorised query from an abusive one. Search frequency, record volumes, query patterns and access times can all provide signals when an account begins behaving differently, provided those signals are collected and reviewed quickly enough.

CPR administrators have not said whether all 8.8 million records were retrieved in a single operation, how many individual searches were made or whether the information has subsequently been distributed or misused. The company’s access remains disabled while the investigation continues.

No arrests or attribution have been announced. For now, the confirmed failure is the misuse of a trusted company’s access to one of Denmark’s most important identity systems, exposing information whose value may persist well beyond the technical recovery from the incident.

×