Denmark CPR register breach exposes 8.8 million people

Denmark CPR register breach exposes 8.8 million people

Danish authorities are investigating a breach of the country's national population register that affects roughly 8.8 million people. The government disclosed the incident on Monday.

The attackers did not break into the system directly. They used the legitimate access of an unnamed Danish company to the Central Person Register (CPR), the central database that assigns every resident a personal identification number. Names, addresses and CPR numbers were compromised. CPR numbers are roughly comparable to Social Security numbers in the U.S.

A register larger than the country

The CPR holds records on about 11 million people. This includes current residents, people who have emigrated and people who have died. Denmark's population is just over six million, so the number of affected records is well above the number of people living in the country today.

Officials said irregular activity on the CPR system was first detected on Friday. Over the weekend, investigators found that the breach took place during September. The government has not said who might be behind it.

Denmark's Data Protection Agency was notified on Sunday. It described the incident as a very large number of automated searches on the system, aimed at identifying valid CPR numbers.

"This is a deeply serious incident," said Christina Egelund, the minister for research, education and digitalisation. She has ordered a broad security review of the system. The national hotline for digital security will also run extended hours, from 8 a.m. to midnight, over the coming days.

Why CPR numbers matter

A CPR number has 10 digits and starts with the holder's date of birth. Danes use it for healthcare, banking and government services. The number is meant to last a lifetime, which raises concern that the risks for affected people could persist for a very long time.

Population-scale breaches of national registries are not new. Similar incidents have been reported in Argentina in 2021, Turkey in 2016, India in 2018 and Israel in 2006, among others.

Supplier access as the weak point

Security experts focused on how the attackers got in.

"This incident demonstrates the inherent risk of highly centralized national databases when private companies are granted direct access to sensitive records," said Dray Agha, senior manager of security operations at Huntress.

"A compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure," he added.

Nathan Davies-Webb, a principal consultant at Acumen Cyber, said that "centralised systems like this should be treated with the utmost importance."

He also praised the government's response so far. "Overall, it is very positive to see the current transparency, especially the extended hours on the digital security hotline," he said. "These behaviours can indicate that response plans are in place and being followed."

Not the first CPR incident

This is the most significant incident involving the CPR system since 2015. That year, two unencrypted CDs with CPR information on more than five million people were mistakenly delivered to the Chinese Visa Application Centre in Copenhagen. Authorities said at the time there was no evidence the data had been copied or leaked.

Our Take

The Danish case shows that a well-protected central system is only as strong as the weakest account allowed to query it. The attackers apparently did not need an exploit. They used a supplier's valid access and ran automated lookups until they had what they wanted. Agha's point about a single supplier account bypassing core controls is the key lesson for any organisation that grants third parties direct access to sensitive records.

For readers outside Denmark, the bigger issue is permanence. Passwords can be reset. A lifetime identifier that includes a birth date cannot. Leaks like this one, the Pentagon DMDC breach or the Arizona court system incident give fraudsters data that stays useful for years. It also comes shortly after the DTU breach, another Danish incident affecting personal data.

It is worth watching whether the security review leads to tighter limits on supplier access, such as rate limits on lookups or better monitoring of automated queries. The fact that the activity ran through September before being detected suggests this is where the gaps were. It also remains to be seen whether Denmark names the company involved or the people behind the attack, and whether the leaked data surfaces in fraud or phishing campaigns aimed at Danes.