Unauthorised users obtained the names, addresses and CPR numbers of around 8.8 million people held in Denmark’s national registry, the digital affairs ministry announced on Monday. The intruders got in by misusing the legitimate access that a Danish company holds to the CPR system. CPR numbers work as Denmark’s social security numbers, and the registry assigns them to newborns and new arrivals.
The figure is far larger than Denmark’s population of about 6 million because the registry covers everyone entered into it since it was set up on 2 April 1968. Around 11 million people are on file, including those who have died or moved abroad. Residents of Greenland have been included since 1972, while people living in the Faroe Islands are not part of the system.
According to the ministry, the unauthorised access lasted for 10 days in September. The CPR administration has cut off the company’s access, brought in specialists and other authorities to reconstruct what happened, and reported the breach to the Danish Data Protection Authority and the police. Jens Myrup Pedersen, a cyber security professor at Aarhus University, described it as “possibly the biggest security breach ever”.
Investigators have a clear starting point. Police can consult the registry’s security log, which is kept for six months and shows which companies have searched the system, and deleted data can be restored from it. Because the breach has been pinned down so precisely, The Local reported that identifying those responsible should not take long. Officers have handled smaller cases before: a year ago they investigated an intern who had abused legal access to the registry to sell details to criminal gangs.
Christina Egelund, Minister for Science, Higher Education and Digital Affairs, told TV2 it was still too early to say whether people would be issued new CPR numbers. The ministry has pointed the public to sikkerdigital.dk and warned that the stolen details could be used in targeted phishing over the coming months. People are advised never to give out passwords or other confidential information by phone or email, even when the person contacting them already knows their name, address and CPR number.
