
Abuse of private firm's access exposed 8.8M records, including those of people who had died or moved abroad
An unauthorized party abused a private Danish company's legitimate access to the country's Central Population Register (CPR), exposing names, addresses, identification numbers, and other personal information about approximately 8.8 million people.
The CPR administration said in a statement [PDF] that it became aware on October 2 of irregular activity during September and established the scale of the breach over the weekend.
In a TV interview last night, digitization minister Christina Egelund said it was too soon to say whether the country would issue all-new CPR numbers, one of the solutions proposed following the breach.
Danish cybersecurity specialist Jan Kaastrup told TV 2 that treating CPR numbers as secrets was a "broken" approach and argued that a number alone should not be accepted as proof of identity. "We live in a digitalized society, and therefore we should have much better identification systems," he said.
Egelund described the company whose access was abused as "small." Private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions set out in the ministry's access terms [PDF]. Eligible recipients include companies, foundations, other legal entities, and individuals conducting business.
However, access concerns a defined group of people identified individually in advance, and recipients must be legally entitled to process the information under the GDPR and Danish data protection law. asked the ministry why such broad access was given.
CPR numbers underpin access to public services and many everyday transactions in Denmark, which has a population of aroun 6 million people. The database includes the information of over 55,000 people living in Greenland who also use CPR numbers for healthcare, tax services, and banking. The ministry said the register contains approximately 11 million records, including people who have died or moved abroad, which explains why the affected total exceeds Denmark's current population.
The ministry also noted that names and addresses of persons who chose to register with name and address protection were not exposed.
The CPR administration blocked the unnamed company's access and said it was working with specialists and relevant authorities to establish what happened. It has notified the Danish Data Protection Agency, and police are investigating.