Breach at Denmark’s population register exposes data on 8.8 million people
Denmark’s Ministry of Research, Education and Digitalisation said attackers obtained names, addresses and CPR numbers for about 8.8 million people by misusing a private company’s legitimate access to the Central Population Register. The ministry said protected names and addresses were not included; the company’s access has been cut off, and police and the Data Protection Agency are investigating. Officials warned that the information could be used for fraud and advised people not to disclose passwords or other confidential information to unsolicited contacts.
What changed The investigation moved from detecting irregular activity on October 2 to establishing the breach’s extent over the weekend and notifying the privacy regulator on October 4.
Why it matters People contacted by fraudsters cannot treat knowledge of their name, address and CPR number as proof of legitimacy; the ministry explicitly warns that the stolen information could support fraud.
What to watch next The regulator is examining how the access occurred and who was responsible for processing the data; those accountability questions remain open.
HelpNet Security ↗