Hackers gained access to the names, addresses, and CPR numbers of 8.8 million people in Denmark through a third-party company with legal registry access. Denmark's national population register, containing sensitive personal data, was compromised in what the digital affairs minister called an "extremely serious incident," according to a recent report by Security Affairs.
The breach affected Denmark's national population register, which holds identifying details for approximately 11 million records, including those of deceased or emigrated individuals. The unauthorized access to CPR numbers, akin to U.S. Social Security numbers, combined with names and addresses, poses a significant risk of identity fraud. The entry point for the attack was identified as a third-party Danish company that had legal access to the registry for its business operations. Authorities are investigating the full scope of the incident and have not yet identified the perpetrators. A concerning detail is that the company's access to the registry has not been revoked, potentially leaving the same vulnerability active. This incident underscores the critical importance of third-party security in protecting sensitive government databases and highlights how such breaches can escalate from privacy concerns to national security issues, especially in the current geopolitical climate.
Source: Security Affairs

