Denmark confirms hackers stole 8 million records from national citizen database
Denmark’s government says hackers breached the Central Person Register and stole data on about 8 million citizens and residents, in what is believed to be the country’s largest data breach.
Danish minister Christina Egelund said in a statement that the breach was a “serious incident,” according to TechCrunch. Hackers stole names, addresses, Danish social security numbers, and other information, the report said.
The affected group includes people living abroad and deceased people, according to TechCrunch. The CPR is a government database of Danish citizens’ information, including the government-issued identity number used for paying tax and accessing other services. Denmark’s current population is about 6 million people, but the database includes records about 11 million people, with some data going back decades.
The Danish government would not say who is behind the breach, TechCrunch reported. The unauthorized access happened in September but was discovered on October 2, according to the report.
The government said the unauthorized access was obtained by “abusing a Danish company’s lawful access to search for information in the CPR system,” TechCrunch reported. Some companies in Denmark have access to the CPR for verifying people’s information with the government.
The incident follows other cyberattacks targeting government national identity databases. TechCrunch noted a 2016 breach affecting millions of Turkish citizens and several exposures of national ID cards and data spilled from India’s national Aadhaar database of citizens.
Editor's Summary
Denmark has confirmed a breach of its Central Person Register that affected about 8 million citizens and residents, with names, addresses, social security numbers, and other data stolen. The government called it a serious incident and said the access came through a Danish company’s lawful CPR access, though it did not identify the attackers. The breach is believed to be Denmark’s largest and adds to previous attacks on national identity databases elsewhere.