Denmark's digitalization ministry has reported that unauthorized parties accessed the Central Person Register (CPR), the national population register, compromising data for approximately 8.8 million individuals. The accessed information includes names, addresses, and personal identification numbers. This incident, reported on October 5, affects both living and deceased persons registered in the CPR.
The attackers reportedly exploited a legitimate access mechanism, utilizing a private Danish company's authorized lookup rights within the CPR system. This suggests a compromise of the company's account or credentials, rather than a direct breach of the CPR system's core infrastructure. Such an attack vector typically involves targeting third-party vendors or service providers that have legitimate access to sensitive government or corporate databases.
The Central Person Register is a foundational database in Denmark, containing critical personal information essential for public administration, healthcare, and various other services. Its comprehensive nature makes it a high-value target for threat actors seeking personally identifiable information (PII) for purposes such as identity theft, fraud, or other malicious activities. The reported scope of 8.8 million individuals represents a significant portion of Denmark's population.
Attacks leveraging compromised third-party access accounts are a common tactic. These incidents often stem from phishing campaigns, credential stuffing, or the exploitation of vulnerabilities in the third-party's own systems, leading to the theft of authentication tokens or login details. Once an attacker gains control of a legitimate account, they can often operate within the bounds of that account's permissions, making detection challenging as their actions may appear to be authorized activity.
Mitigation strategies for this class of attack typically involve robust security practices for all entities with access to sensitive systems. This includes implementing multi-factor authentication (MFA) for all accounts, regular security audits of third-party vendors, strict access controls based on the principle of least privilege, and continuous monitoring for anomalous account activity. Furthermore, organizations are advised to conduct regular employee security awareness training to guard against social engineering tactics.
The Danish digitalization ministry has reportedly advised individuals never to disclose their personal identification numbers unless absolutely necessary. This guidance underscores the ongoing risk of identity-related fraud following such a data compromise. The incident highlights the persistent challenge of securing interconnected digital ecosystems, where the security posture of one entity can directly impact the data integrity and privacy of an entire population.






