SlovakNews

Science & Tech · Denmark

Denmark registry breach exposes records of up to 8.8 million people

Hackers used a Danish company’s authorised access to enter the national registry. Reports put the number of affected records at about 8 million to 8.8 million.

Live Version: 1Sources: 2Perspectives: 2Updated:
Foto: The Straits Times · source

What's new

  • Denmark discovered the Central Person Register breach on October 2.
  • An investigation has been launched and authorities are assessing the full scope.
  • The hackers have not been identified.
  • The compromised access had not been revoked when the incident was reported.

Hackers obtained unauthorised access to Denmark’s Central Person Register in September and stole most of its contents, including names, addresses and government-issued identity numbers, according to TechCrunch. The Danish government discovered the breach on October 2; those responsible had not been publicly identified when the incident was reported on October 5.1

Millions of records affected

The Straits Times reported that information belonging to around 8.8 million registered people was obtained, while TechCrunch put the affected total at about 8 million citizens and residents. The reports said the exposed population included people who had died, emigrated or were living abroad. The different figures both exceed Denmark’s current population of approximately six million because the registry also holds historical records.12

The Central Person Register contains records for about 11 million people, including information accumulated over decades, according to TechCrunch. The stolen material included names, addresses, CPR numbers – Denmark’s social security numbers – and other information. The register is a government database holding details about Danish citizens and their official identity numbers.12

Company access used as entry point

Both reports said the intruders reached the registry through an unnamed Danish company that was legally permitted to search its records. Some Danish companies receive such access to verify people’s information with the government, TechCrunch reported. The Straits Times said the company itself was hacked, while the Danish government described the intrusion as involving the abuse of the company’s lawful access.12

The Straits Times reported on October 5 that the access used in the breach had not been revoked. It also said an investigation had begun. The Danish government would not identify those behind the intrusion, according to TechCrunch, while The Straits Times reported that the hackers had not yet been identified.12

Authorities assess the scope

Digital affairs minister Christina Egelund said authorities were working to establish the incident’s full extent. “This is an extremely serious incident,” she said. TechCrunch reported that the breach was thought to be the largest in Denmark’s history, although that assessment was reported by one source.12

The scale remains subject to differing published estimates. The Straits Times referred to around 8.8 million registered people whose names, addresses and CPR numbers were obtained. TechCrunch described about 8 million affected citizens and residents and said most of the register’s contents had been stolen.12

Why it matters

The breach concerns identity information held by a European government and includes records connected to people living outside Denmark. Its reported reach is larger than Denmark’s current population because the database also includes deceased and emigrated people and information dating back decades.12

Version history

  1. version 1 ·