Skip to content

Security3 publishers2 min readPublished

Automated searches through one company's access exposed 8.8 million people in Denmark's CPR register

Denmark says a domestic company's legitimate access to its population register gave intruders the names, addresses and ID numbers of 8.8 million people. The numbers are meant to last a lifetime, so the exposure outlives any fix to that company's connection.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Automated searches through one company's access exposed 8.8 million people in Denmark's CPR register
Generated illustration

What happened

  • Denmark's Data Protection Agency, notified on Sunday, described a very large number of automated searches aimed at identifying valid CPR numbers.
  • Officials first detected irregular activity on Friday, and weekend investigations found the breach itself took place during September.
  • The register covers about 11 million people, including emigrants and the dead, while Denmark's current population is just over six million.
  • Christina Egelund, minister for research, education and digitalisation, ordered a broad security review and extended the digital security hotline to 8 a.m. to midnight.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability Whoever ran the searches now holds CPR numbers matched to names and addresses, and that number is the identifier Danish healthcare, banking and government services use.
  • exposure People who have left Denmark or died are among the exposed, at least about 2.7 million of them by the register's own totals.
  • decision Egelund's security review now has to decide whether private companies keep direct query access to the register, and with what limits on search volume.

Each CPR number is 10 digits long and begins with the holder's date of birth [7]. That format makes the agency's described search easier. For any real birth date, only the digits after it have to be tried [3]. According to the government, those searches ran through a connection the register already accepted as legitimate [2].

"This incident demonstrates the inherent risk of highly centralized national databases when private companies are granted direct access to sensitive records," said Dray Agha, senior manager of security operations at Huntress [10]. "A compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure," he said [11].

Agha's compromised-account scenario fits the government's account but goes further than it. Officials did not name the company, say how the perpetrators obtained its access, or comment on who they are [2][5]. A stolen login and a company misusing its own access call for different fixes.

The 8.8 million affected are about 80 percent of the register's roughly 11 million entries [1][3][1]. The Record lists other population-scale registry breaches, in Argentina in 2021, India in 2018, Turkey in 2016 and Israel in 2006 [9]. Denmark's is the only one in that report tied to a private company's access [2]. On this evidence, third-party access is the weak point in one national register, through one company [2].

The Record calls this the most significant CPR incident since 2015. That year, two unencrypted CDs carrying the CPR details of more than five million people ended up by mistake at the Chinese Visa Application Centre in Copenhagen [13]. Authorities said at the time there was no evidence the data had been copied or leaked [14]. This time the government says the data was compromised [2].

Nathan Davies-Webb, a principal consultant at Acumen Cyber, praised the government's transparency so far. "These behaviours can indicate that response plans are in place and being followed," he said [12].

What to watch

  • Whether Danish officials name the company and say if the perpetrators stole its credentials or the company misused its own access.
  • What Egelund's security review decides about private-company access to the CPR, including any cap on automated search volume.
  • Any sign that the September search results are being sold or used for fraud at banks or healthcare services that rely on CPR numbers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories