On October 5, Denmark’s Ministry of Digitalization reported a significant data breach, affecting approximately 8.8 million people. Unauthorized parties accessed the national population register, compromising names, addresses, and personal identification numbers. This breach involved both living and deceased individuals.
Unauthorized Access via Company Account
The breach occurred through a Danish company’s authorized access to the Central Person Register (CPR). The ministry has reiterated the importance of safeguarding passwords and other sensitive information, warning against sharing such details with suspicious emails or phone calls.
In response, access for the implicated company has been suspended, and the incident has been reported to Datatilsynet, Denmark’s data protection authority. Law enforcement is actively investigating the matter.
Extent and Method of Data Breach
According to Datatilsynet, a large number of automated lookups were conducted to identify valid CPR numbers. This activity lasted about ten days in September and was facilitated through a small Danish firm. Anomalies were detected by a register employee on October 2, and the scale of the breach was confirmed over the subsequent weekend.
The breach potentially affects about 80% of the register’s 11 million records, covering living residents, expatriates, and deceased individuals. However, it did not include those with name-and-address protection, which limits data disclosure to private entities.
Preventive Measures and Future Actions
The Ministry of Digitalization advises individuals to remain vigilant against fraudulent communications and to avoid sharing sensitive information. Citizens are encouraged to set up credit warnings through borger.dk to prevent unauthorized credit applications.
In light of the breach, the ministry has initiated preventive measures and is conducting a comprehensive review of the register’s security protocols. Datatilsynet is assessing the breach to determine the causes and responsible parties.
The minister responsible for digitalization, Christina Egelund, acknowledged the inadequacy of existing security measures and emphasized the need for improved safeguards. The possibility of issuing new CPR numbers to affected individuals remains under consideration.
