Data breach exposes personal details of 8.8M people in Denmark

Attackers managed to gain access to Denmark’s population register, allowing them to view and copy the personal details of 8.8 million residents.
According to a press release that was published by the Danish government on Monday, a “serious security incident” took place at the Central Personal Register (CPR) in September. The administration got wind of it on the evening of Friday, October 2nd.
By abusing a Danish company’s legal access to search information in the CPR system, hackers managed to access names, addresses, CPR numbers, and other personal information of approximately 8.8 million citizens, both deceased and alive.
The CPR contains information from about 11 million residents.
Security experts and authorities are reviewing the incident. Primary findings shows that the breach didn’t involve names and addresses of individuals who had chosen to register with name and address protection.
The incident has been reported to the Danish Business and Digitization Committee. Specialists are currently in the process of mapping the event. They are also looking into the cybersecurity measures that were in place at the time of the incident.
“Together with all relevant authorities, we are in the process of mapping the full extent of the incident. We have already launched initiatives in relation to the CPR to prevent similar incidents. In addition, I have asked for a thorough security review of the CPR system. I would urge all citizens to be aware now and in the coming time,” Minister of Research, Education, and Digitization Christina Egelund said in a statement on Monday.
As of writing, no ransomware extortion group or operation has claimed responsibility for the incident.
Victims are advised not to provide their passwords or other confidential information to people who claim to work at the CPR via telephone, email, or text message.
Last week, hackers accessed the identity and access management system of the Technical University of Denmark (DTU) and downloaded a large amount of data, potentially affecting up to 200,000 current and former users.
“This is a serious attack on DTU, and we deeply regret the uncertainty it is causing for the people whose information may have been affected. Our first priority has been to establish the extent of the attack, limit its consequences, and ensure that those affected are notified and know what steps to take,” University Director Bjarke Bak Christensen said in response.