Denmark's citizen database hacked, data of 8M stolen
What's the story
The Danish government has confirmed a major data breach, with hackers stealing information from its Central Person Register (CPR). The attack impacts nearly 8 million citizens and residents of Denmark, including those living abroad and deceased individuals. Danish minister Christina Egelund described the incident as a "serious incident," that allowed cybercriminals to access names, addresses, and social security numbers, among other details.
Database details
What is Central Person Register (CPR)?
The CPR is a government-managed database containing information about Danish citizens, including their unique identity number for tax payments and other services.
Though Denmark's population is around six million, the database has information on 11 million people, some of which dates back decades.
The data breach is believed to be the largest in Denmark's history, raising alarms over cybersecurity.
Access details
Breach occurred in September
The breach occurred in September but was only discovered on October 2.
The Danish government has not revealed the identity of the hacker(s), but said that unauthorized access was gained by "abusing a Danish company's lawful access to search for information in the CPR system."
This incident highlights the potential risks associated with granting companies access to sensitive government databases for verification purposes.