
(Oct 5): Denmark suffered a major data breach that gave unauthorised individuals access to names, addresses and personal identification numbers belonging to about 8.8 million people registered in the country’s central population database.
The breach occurred after unidentified individuals misused a private Danish company’s legitimate access to search the Central Person Register, known as CPR, the government said in a statement Monday.
The company has since been blocked from the system while police investigate the matter, with authorities saying it’s too early to determine who was behind the breach.
“This is a deeply serious incident,” Digitalisation Minister Christina Egelund said. She has ordered a comprehensive security review of the CPR system and urged Danes to be vigilant about suspicious calls and emails.
The CPR system is a cornerstone of Denmark’s highly digitised public sector. Every resident is assigned a unique 10-digit CPR number that is widely used to identify individuals when dealing with government agencies, banks and healthcare providers. While Denmark has a population of about six million, the register contains records on roughly 11 million people, including those who have died or moved abroad.
The administration first detected irregular activity on Oct 2 and determined over the weekend that unauthorised searches had taken place during September. People registered in the system for name and address protection were not exposed, it said.
Uploaded by Arion Yeow