
Unknown users have pulled names, addresses and ID numbers on about 8.8 million people from Denmark’s Central Person Register (CPR). They abused a small Danish company’s legal access to the register. Denmark’s digitalisation ministry announced the breach on Monday. The CPR administration has cut off the company, and the police are investigating.
Denmark has about 6 million residents, according to Statistics Denmark. The register holds about 11 million records, because it also keeps people who have died or moved abroad. The breach did not reach people who chose name and address protection, the ministry said.
“This is a deeply serious incident,” said Christina Egelund, the minister for science, higher education and digital affairs.
Found through an invoice
The lookups ran for ten days in September. The company’s account made well over 14 million CPR lookup attempts, and 8.8 million returned a record, officials told a press briefing on Tuesday, TV 2 reported. Companies pay for every lookup, and the CPR breach came to light when the CPR administration billed the firm.
“I can confirm that it is during invoicing on Friday evening that a very, very large amount is billed, which alerts you that there has been very large activity during September,” said Mikkel Leihardt, a department head at the ministry.
The ministry spotted the irregular activity on the evening of 2 October. It established the scale over the weekend. Officers from the National Unit for Special Crime visited the company on Saturday evening to secure evidence. Henriette Erbs, a unit head, told the briefing that police have identified no one and charged no one. They are contacting police in other countries.
Private companies with a legitimate interest can get CPR data under section 38 of the Danish Civil Registration System Act. Under the ministry’s access terms, that covers a specified group of people the company has identified individually in advance. The ministry has not named the company.
A CPR number is no longer enough
Egelund has ordered a security review of the CPR system, with no deadline. She told TV 2 it was too early to say whether people would get new CPR numbers. She said the breach did not touch systems that use MitID, the national digital login, such as those in healthcare.
Laila Reenberg leads Styrelsen for Samfundssikkerhed, Denmark’s agency for civil security. She told companies and authorities to stop accepting a CPR number on its own as proof of identity. Pharmacies, which accept the number alone, must find other ways, she said.
“You cannot use it to authorise things, to buy something or to get sensitive personal information,” Reenberg said.
Jan Kaastrup, a private digital investigator, called the system “broken” in an interview with TV 2.
“We live in a digitalised society, and therefore we should have much better identification systems,” Kaastrup said.
Egelund urged Danes to be wary of calls, emails and links, and warned that criminals could use the data for phishing. In August, ShinyHunters took 1.6 million records from RingCentral with a phone call. That month, a stolen login cost France’s tax agency data on 678,000 people. Hackers also hit Liechtenstein’s beneficial owners register.