Denmark’s national ID system breach exposes personal data of 8.8M
Attackers used a company’s credentials to pull records on about 8.8 million people from Denmark’s national ID registry.
Denmark is reviewing security around its Central Person Register after unauthorized parties used a company’s access credentials to query the national citizen registry for about 10 days in September. More than 14 million searches returned records on approximately 8.8 million people, including residents, deceased people, and people who moved abroad; protected names and addresses were not affected. Administrators discovered unusual activity on October 2, the company’s access was cut off, and the National Special Crime Unit is investigating. Officials warn exposed CPR numbers could enable fraud and advise organizations not to rely on a CPR number alone.
- About 8.8 million CPR records were returned from over 14 million searches.
- Unauthorized access lasted about 10 days in September and was found October 2.
- The unnamed company’s access to the CPR system has been revoked.
- Officials advise MitID, two-factor authentication, or one-time codes instead of CPR alone.
Full article196 words · extracted from csoonline.com · click to collapse
Denmark is reviewing security controls around its national citizen registry after unauthorized parties exploited a company’s access credentials to harvest records on approximately 8.8 million people over a 10-day period. The breach covers people living in Denmark as well as individuals who have died or moved abroad, while people with protected names and addresses were not affected.
The unauthorized activity took place for about 10 days in September and was discovered on October 2 after CPR administrators noticed unusual activity. Authorities subsequently found that more than 14 million searches had been made through the company’s account, with about 8.8 million returning records.
The affected company has since been cut off from the CPR system, while Denmark’s National Special Crime Unit is investigating. Authorities have not identified those responsible, but officials have warned that the exposed CPR numbers could enable fraud and identity-related abuse.
The incident is also forcing Denmark to reconsider how CPR numbers are used for identity verification. Officials are advising organizations not to rely on a CPR number alone and to use stronger mechanisms such as MitID, two-factor authentication, or one-time codes.
A broader security review of the CPR system is now underway.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4231797/denmarks-national-id-system-breach-exposes-personal-data-of-8-8m.html