Danish Population Register Breach Shows How Supplier Access Can Expose Millions
Denmark is investigating a data breach affecting around 8.8 million people after unauthorised users gained access to its national population register, the government said on Monday. The attackers exploited the legitimate access of an unnamed domestic company to the Central Person Register (CPR), compromising names, addresses and CPR numbers. These 10-digit numbers begin with a person's date of birth and are used for healthcare, banking and government services. They are roughly comparable to Social Security numbers in the United States.
Officials first detected irregular activity on Friday and determined over the weekend that the breach occurred during September. Denmark's Data Protection Agency described it as a very large number of automated searches aimed at identifying valid CPR numbers. No perpetrators have been named. Research, education and digitalisation minister Christina Egelund called it a deeply serious incident, ordered a broad security review and extended the digital security hotline hours from 8 a.m. to midnight. Because CPR numbers are meant to last a lifetime, there are fears the risks could have a very long tail.
Experts pointed to the supplier connection. Dray Agha of Huntress said a compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure. The source notes similar national registry breaches in Argentina, Turkey, India and Israel.