The Danish government confirmed a data breach affecting its Central Person Register (CPR), with hackers stealing records of approximately 8 million citizens and residents. The breach, discovered on October 2, includes sensitive information such as names, addresses, and Danish social security numbers, impacting both current residents and deceased individuals, according to techcrunch.com.
The breach occurred in September through unauthorized access gained by exploiting a Danish company's legitimate access to the CPR system. The CPR database holds information on about 11 million people, exceeding Denmark's current population of 6 million, as it includes historical data spanning decades. Danish minister Christina Egelund described the incident as "serious," emphasizing the scale and sensitivity of the compromised data.
This incident represents the largest data breach in Denmark's history and aligns with a pattern of cyberattacks targeting national identity databases worldwide. Comparable breaches include the 2016 hack of Turkey's citizen database and multiple exposures of India's Aadhaar system. The CPR database is critical for tax payments and accessing government services, making the breach a significant national security concern.
The Danish government has not disclosed the identity of the attackers or the company whose access was abused. The breach's discovery on October 2 triggered immediate investigations and security reviews to prevent further unauthorized access, as reported by techcrunch.com.