Large-scale data leak occurred in Denmark from the central population registry

Large-scale data leak occurred in Denmark from the central population registry
Photo: illustrative

A large-scale incident involving the security of the central population registry CPR has been discovered in Denmark. Unauthorized individuals gained access to names, addresses, personal CPR numbers and other data of approximately 8.8 million people registered in the system.

The Ministry of Research, Education and Digitalization of Denmark reported this on October 5.

Access was not obtained through a direct hacking of the state register itself. According to preliminary data, the unknown individuals took advantage of the legal access of a private Danish company that had the right to search for information in the CPR. The authorities have not yet disclosed the name of the company or the individuals responsible for the incident.

The figure of 8.8 million refers not only to current residents of Denmark. The central register contains about 11 million records, including data of people who currently live in the country, have moved abroad or have died.

At the same time, according to the results of the initial check, the unauthorized access did not cover the names and addresses of people who had officially established protection of this data in the register.

Suspicious activity in the system was recorded during September, and the CPR administration noticed it on the evening of October 2. Over the following days, specialists determined the scale of the unauthorized access.

The private company's access to the CPR was subsequently blocked. The registry administration reported the incident to the Danish data protection regulator, and the case is being investigated by the police together with other competent authorities.

The authorities also launched an additional check of the system and introduced measures to prevent a repeat of a similar access scheme.

The CPR number is a personal identifier widely used in citizens' interactions with government agencies, banks and other organizations. Danish authorities urged citizens to be especially careful with suspicious calls and messages and not to pass passwords or other confidential information to people who may use the stolen personal data for more convincing fraud.

Based on materials from: Ministry of Research, Education and Digitalization of Denmark, Bloomberg.