Denmark breach exposes CPR data for 8.8 million people
Unauthorised parties accessed names, addresses and CPR numbers for about 8.8 million people through a Danish company’s legitimate connection to the national register, Danish authorities said. The incident affects records of current residents, emigrants and deceased people; authorities have cut off the company’s access and launched an investigation.
Bottom line — With 8.8 million records affected, Denmark is reviewing CPR security while police investigate who misused the company’s access.
Go deeper 7
-
The CPR administration detected unusual activity on 2 October and confirmed the scale of the access over the weekend, according to Cyber Security News.
-
Denmark’s CPR holds about 11 million records, including people who have died or moved abroad, Cyber Security News reports.
-
Authorities have not named the company or identified the attackers, according to Cyber Security News.
-
The official review found that names and addresses of people with name and address protection were not accessed, Daily CyberSecurity reports.
-
Authorities have warned people not to share passwords or other confidential information in unexpected calls or emails, The Local Denmark reports.
-
The breach has been reported to Denmark’s Data Protection Authority, and police are investigating, according to The Local Denmark.
-
Digitalisation Minister Christina Egelund has requested a thorough security review of the CPR system, Cyber Security News reports.