Denmark Data Breach Exposes 8.8M Records via Legitimate API Access
Attackers exploited a Danish company's authorized access to the national CPR database, compromising personal data of nearly 9 million individuals. Authorities warn of potential misuse of stolen identifiers.
TL;DR
- 8.8 million Danish personal records accessed through legitimate business API
- Includes names, addresses, and CPR numbers of living and deceased individuals
- Attackers abused a third-party company's lawful data query permissions
- No evidence yet of data encryption or anonymization at point of access
- Authorities advise citizens to monitor accounts and enable fraud alerts
Denmark's digitalization ministry disclosed a massive data compromise affecting over 8.8 million individuals, including both living citizens and deceased persons. The breach occurred when unauthorized actors gained access to the Central Person Register (CPR) by exploiting legitimate data query permissions held by a private Danish company.
Unlike typical cyberattacks that involve breaking into systems, this incident highlights the growing risk of supply chain vulnerabilities through authorized access channels. The compromised data includes highly sensitive personally identifiable information (PII) such as full names, residential addresses, and unique civil registration numbers essential for Danish identity verification.
Attack Vector and Compromised Data
- Intruders accessed Denmark's national population register through a third-party company's legitimate API credentials
- Data extraction included names, physical addresses, and CPR numbers for approximately 8.8 million individuals
- The breached records encompass both current residents and historical entries of deceased persons
- No indication that attackers used malware, phishing, or system exploits to gain initial access
- Compromised data represents nearly the entire Danish population registry
Security Implications for Organizations
- Highlights risks of third-party access provisioning without proper monitoring and access limitations
- Demonstrates how legitimate business partnerships can become attack pathways
- Shows importance of implementing just-in-time access and principle of least privilege for external integrations
- Reveals potential gaps in audit logging for authorized data queries at scale
- Underscores need for real-time anomaly detection on legitimate access channels
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.