Everything we know about the cyber attack that hit 8.8m Danes

The Danish government has confirmed a "deeply serious incident" which exposed personal data belonging to 8.8 million citizens.

Hackers accessed the Central Person Register (CPR) by taking advantage of a Danish company's access to the system, the government admitted in a statement on 5 October.

The data accessed includes names, addresses, CPR numbers – akin to national insurance numbers that also link to healthcare and other services – and other data on 8.8 million people registered on the system in Denmark.

Minister of research, education and digitalization Christina Egelund said in a statement translated to English that it was a "deeply serious incident" and that authorities were in the "process of mapping the full extent of the incident."

Danish data breach: What happened?

The attack was spotted on Friday night, with CPR staff observing irregular behavior on systems during September. Nathan Davies-Webb, principal consultant at Acumen Cyber, said this discovery gap is a highly concerning aspect of the breach.

"While this may not be a direct factor in this case, delays are common when a breach originates from a third-party."

Over the weekend following further investigation, it became clear that hackers had managed to access the names, addresses and CPR numbers of 8.8 million citizens.

Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.

While Denmark's population is about six million, the system includes people who have moved away from Denmark as well as those who have passed away, holding data on roughly 11 million people in total. The government said the hackers did not access the names and addresses of people who asked for address protection.

As the investigation is in early stages, the government said it wasn't possible to say who was behind the attack. However, officials said the threat actor(s) took advantage of a system that allows Danish companies to legitimately search for information within the CPR system.

The suggestion is the attackers gained access by targeting a private Danish company to target the CPR system.

Dray Agha, senior manager of security operations at Huntress, said the incident shows the risk of developing a centralized national database that offers direct access to third parties.

"A compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure," Agha said.

"To defend against this threat, governments and businesses must also strictly limit what external partners are allowed to view," Agha added. "They must also monitor these systems continuously to detect unusual search patterns before millions of records are extracted."

What next?

The government reported the incident to the Danish data protection regulator, and local police are investigating. Protections have been put in place to better protect the CPR, the government added.

In light of the breach, Egelund warned Danes to "be aware now and in the future," with a government statement warning citizens against giving out passwords or other confidential information over the phone or email to an unknown person, even if they have personal details like your address or CPR number.

Jamie Akhtar, CEO and co-founder of CyberSmart, agreed that Danes should be on the alert for phishing emails, texts and calls that claim to come from banks or public authorities.

This is a common tactic employed by threat actors in the wake of data breaches, with groups capitalizing on freely available information to conduct follow-up attacks on those impacted.

"Knowing your name, address or identification number does not make a caller trustworthy," Akhtar added.

"Customers must verify requests through an official website or a known telephone number, check accounts for unusual activity and report suspected fraud promptly."

FOLLOW US ON SOCIAL MEDIA

You can also .

Original source Everything we know about the cyber attack that hit 8.8m Danes

Back to home