Denmark’s CPR administration says unauthorised parties obtained names, addresses and CPR numbers for about 8.8 million people in the national population register. The route in was a Danish company’s legitimate right to search the system.
The Ministry of Research, Education and Digitalisation said in a press release dated Oct. 5 (in Danish) that the Central Person Register had confirmed a serious security incident. Those affected include living, emigrated and deceased people; the register holds about 11 million records. Names and addresses of people with name and address protection are not included.
The CPR administration learned on the evening of Friday, Oct. 2 that the system had shown irregular behaviour during September, and confirmed the scope over the weekend. The ministry says the access came from misusing a private company’s lawful right to look up data. The administration has stopped that company’s access and reported the incident to the Danish Data Protection Agency, and police are investigating. Minister Christina Egelund has ordered a thorough security review of the system.
The ministry tells residents never to give passwords or confidential details to callers or email senders, even when they know the resident’s name, address and CPR number. A cyber hotline is open 8 a.m. to midnight.
Why it matters: a CPR number is used across banking, healthcare and government services, and the ministry’s own warning shows the combination of name, address and number is now enough to make a pretext call sound credible.
Our read: the failure point the ministry describes is the scope and monitoring of a third party’s search rights, not a break through the register’s perimeter. Ask your own suppliers who can run lookups against your data, what a normal day’s volume is, and who notices when it changes. A French case also began with legitimate credentials in ANSSI Report on French Tax Breach Cites Staff Credentials, and we covered a supplier-side incident in Bitget’s Loss Grows to $388M via a Security Product.