Other SBS Sports · 3h ago

Denmark Suffers Massive Data Breach Exposing 8.8 Million Records—More Than Its Entire Population

Key Points
  • An unidentified intruder breached Denmark's civil registration system (CPR) over a ten-day period, exfiltrating personal data of roughly 8.8 million individuals.
  • The scale of the breach surpassed Denmark's living population of 6 million because the database stores historical records of deceased citizens and emigrants.
  • Authorities confirmed the breach occurred via legitimate access credentials of a private contractor, prompting admissions from the government regarding lax security oversight.
Summary A massive cybersecurity incident in Denmark has compromised the personal data of approximately 8.8 million people—a staggering figure that exceeds the country's current living population of roughly 6 million. According to reports citing the Copenhagen Post, an unidentified intruder gained unauthorized access to Denmark's central Civil Registration System (known locally as the CPR, or Det Centrale Personregister) for about ten days last month. The stolen data includes sensitive personal records such as names, physical addresses, and CPR numbers, which serve as the Danish equivalent of national identification or resident registration numbers. Because the CPR registry maintains historical records encompassing deceased individuals and emigrants—holding around 11 million profiles in total—the breach exposed far more individual records than Denmark’s active population count. Denmark's Minister for Digital Affairs, Christina Egelund, classified the breach as an "extremely serious" incident. Preliminary findings revealed that the perpetrators infiltrated the CPR system by exploiting legitimate access privileges assigned to a small private company. An employee within the CPR administrative department detected irregular activity on October 2 and alerted authorities, prompting an immediate revocation of the company's system credentials. Minister Egelund acknowledged that security oversight surrounding the private contractor's access was deficient, pointing out that because the suspicious activity persisted for days, it should have been caught much earlier. Officials have withheld the contractor's name due to the ongoing investigation and declined to comment on whether the perpetrators acted with criminal or hostile intent. In South Korea, where the story drew international news coverage, the incident resonated strongly due to the nation's own strict resident registration number system and heightened public sensitivity toward large-scale data breaches.
Sponsored · Ad