Hackers breach Denmark's national registry, accessing personal data of 8.8 million people
Denmark's digital affairs ministry says hackers used a private company's legitimate access to search the Central Person Register, obtaining names, addresses and CPR numbers of around 8.8 million registered people; irregular activity was detected on October 2 and police are investigating.
Hackers broke into Denmark’s national population registry and gained access to personal information on around 8.8 million people, the country’s digital affairs ministry said on Monday.
“The administration of the national registry (Central Person Register) has found that unauthorised individuals obtained illegal access in particular to the names, addresses, and CPR numbers of around 8.8 million registered people,” including those who have died or emigrated, the ministry said in a press release, referring to Denmark’s social security numbers.
The attackers reached the registry by misusing the legitimate access of a Danish company, the ministry said. The irregular activity was detected on October 2, and the investigation over the weekend established that unauthorised automated searches had taken place during September. Denmark’s Data Protection Agency, Datatilsynet, said it had received a report on the incident on Sunday and was examining how the searches became possible and who was responsible.
“This is an extremely serious incident,” Digital Affairs Minister Christina Egelund said in the press release. “Together with all the relevant authorities, we are in the process of mapping out the full extent of the incident.” She has ordered a comprehensive security review of the CPR system and urged Danes to be vigilant about suspicious calls and emails.
Denmark has a population of around six million, but the national registry holds information on about 11 million people, including the deceased and those who have emigrated. Names and addresses covered by special privacy protection were not exposed. An investigation has been launched and the hackers have not yet been identified; the ministry said it was too early to say who was behind the incident.
More on this topic: all Technology stories

