Denmark says hackers stole data on 8.8 million people from its national registry
TLDR
- Denmark's Central Person Register (CPR), the national database holding every citizen and resident's identity information, was breached and most of its contents stolen.
- About 8.8 million people are affected, more than Denmark's entire population of six million, because the register also holds records on the deceased and people who have emigrated.
- The breach happened in September but was only discovered on 2 October; the government says it is the biggest data breach in Danish history.
- Attackers got in by abusing a Danish company's own legitimate access to the CPR system, not by hacking the register directly.
Denmark's digital affairs minister, Christina Egelund, called the breach a "serious incident" that let hackers steal names, addresses, Danish social security numbers and other personal information from the CPR, the government database used to issue the identity numbers citizens need to pay tax and access public services.1 The CPR holds data on roughly 11 million people even though Denmark's population is about six million, since the register retains records on people who have died or moved abroad, and the September breach affected roughly 8.8 million of them.2
The Danish government has not said who carried out the attack. Officials said the unauthorised access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system," referring to the fact that some private companies in Denmark hold permitted access to the register to verify people's details with the state.1 Danish news agency Ritzau reported that the exposed register also includes information on church membership and details of legal incapacitation and restrictions on legal capacity.2
The intrusion is thought to be the largest data breach in Denmark's history, following a pattern of attacks on other countries' national identity databases, including a 2016 breach affecting millions of Turkish citizens and repeated exposures of India's Aadhaar national ID system.1
Why it matters: a breach of a national identity register through a trusted third party's own access, rather than through a direct hack of the government system itself, exposes a soft spot that is much harder to patch than a single vulnerable server, since it depends on policing who else holds legitimate access to citizens' most sensitive identifying data.
Sources
- Hackers steal 8 million citizens' records from Danish government database (TechCrunch)
- Denmark: Data of millions compromised in hack (Deutsche Welle)