Denmark has confirmed a major data breach involving its Central Population Register, known as CPR, after unauthorized parties accessed personal records belonging to about 8.8 million people. The exposed information includes names, addresses, and CPR numbers, according to an official statement published on October 5, 2026.

The figure exceeds Denmark’s population of roughly six million because the register also holds records of people who have moved abroad and those who have died. Officials said the CPR system currently contains approximately 11 million registered people, meaning the incident affected a large share of its records.

…

The attackers misused a private Danish company’s lawful access to search the CPR system during September. Authorities have not described how the unauthorized parties obtained or used that access, leaving the initial entry method unknown.

The confirmed route is important: this was misuse of an approved company connection, not a publicly confirmed software flaw in the register. The ministry has not disclosed the company’s name, linked the incident to a known threat group, or identified a specific vulnerability.

…

Research, Education and Digitalization Minister Christina Egelund described the incident as deeply serious. She informed Parliament’s Business and Digitalization Committee and requested a thorough security review of CPR. Officials said preventive measures had already started, without detailing their technical scope.

…

Names, addresses, and national identification numbers can make fraudulent messages and calls appear convincing. Cybersecurity News’ coverage of the Pentagon data breach similarly highlights the risks when personal records include identity numbers, while its phishing prevention guidance explains common warning signs.

…

Archived

    • BarneyPiccolo@lemmy.today
      link
      fedilink
      English
      arrow-up
      2
      ·
      10 hours ago

      We know, it happens in America nearly every day, and those are just the ones we hear about. I just assume bad guys already have every bit of data on me already.

  • TankovayaDiviziya@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    16 hours ago

    Cybersecurity isn’t taken seriously enough especially by the public sector. Most fraud aren’t done the old school way of physical heist, it’s done online now. AI and quantum computers will only make it worse.

    That said, as much as people rightfully hate AI, there is a point that slowing down AI could be a matter of national security. For all we know, it could be a state actor involved in the hacking of the Danish registry. We must slow down the development of AI, but undemocratic bad faith actors who don’t care about public opinion won’t slow it down.

  • bstix@feddit.dk
    link
    fedilink
    English
    arrow-up
    3
    ·
    17 hours ago

    Having used the system some time ago, I’m not too worried. It only shows the name and latest address. Basically like the white pages but with a soc.sec.ID instead of the phone number.

    It lacks info on a lot of people, because some people aren’t too good at reporting when they move, and some are hidden for legal reasons.

    The most dangerous thing would be if the data is sold to stalkers, because it does have more addresses than the white pages.

    The soc.sec.no. includes birthday and gender, so it can also be used for targeting scams.

    Anyway, it’s not like this data wasn’t already available in one way or another. The breach just made it easier for whoever did it.

  • SorteKanin@feddit.dk
    link
    fedilink
    English
    arrow-up
    17
    ·
    1 day ago

    For those who are not familiar with the Danish citizen register: Basically it’s an ancient system made way before computers were a thing and it’s just not been updated to modern standards because politicians never prioritize things before they blow up in their face.

    The crux of the issue: In Denmark, your personal ID is not just an ID, it is also an access token. So you need to keep your ID number secret, otherwise others can use it to look up your personal information. Like, imagine your username was also your password, that’s how dumb this system is. Add to this the fact that certain private companies get priveliged access to the citizen register for reasons and anyone with a few braincells could predict this happening 20 years ago.

    • wolfpack86@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      Well and the number space is your birthday and then 4 digits… But ending in odd numbers for men and even for women.

      So it was already not very secure considering there’s numerically only 5000 options once you know almost anything about a person you want to target.

      • SorteKanin@feddit.dk
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        That’s only a problem because it is used as a password. If it was actually just a pure ID and didn’t give access to any information, then it wouldn’t matter. Okay, you could guess my ID if you had my birthdate - so what? The ID is useless, it’s just an ID.

        • wolfpack86@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 hours ago

          Yes of course.

          I also don’t understand why MitID got rid of username/password before phone authentication (like nemID had).

          That was a bit of a regression

          • SorteKanin@feddit.dk
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 hours ago

            MitIDs password that doubles as an ID has also always been super weird to me. No idea why they did it like that.

            Maybe so you don’t need to remember both a username and a password? But that’s such a pathetic reason.

    • Ontimp@feddit.org
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      Haha I work in German government IT and have a colleague who likes to point to Denmark as an example for how good things could be here. I’ll show him this next time he needs to put down the rose glasses.

      That said, it’s the same in Germany, only that citizen data is kept with municipalities, so we have ca. 11.000 different such shitty systems built decades ago instead of one - which makes it less attractive and damaging to compromise any given one, I guess.

      At least, however, we don’t have a citizen ID such as the one you describe, that could be used to identify people uniquely.

      • theoretiker@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        18 hours ago

        With NOOTS Germany will move toward a less decentralized service with municipalities being able to share data between them more easily. I hope though that BSI pressures for it to be secure by modern standards.

      • Richie Rich@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        20 hours ago

        If you were to combine those two pieces of information, you could definitely identify a person unambiguously. Just because our government is too incompetent to combine the information doesn’t mean hackers won’t do it. But soon we’ll have the centralized BundID—to make things easier for hackers.

        • Ontimp@feddit.org
          link
          fedilink
          English
          arrow-up
          2
          ·
          18 hours ago

          I know and what I’m sayin is that this is by design. It’s not only about competence, competence can be bought. It’s structurally difficult because various different ministries and independent bureaucracies would need to decide to cooperate and do tedious work to combine data sets like this. It’s not a magical antidote but a structural impedance that is supposed to make abuse more difficult, obviously not impossible.

          And BundID does not entirely change to his. BundID does not assign you a unique identifier either. You get a temporary process-based ID that is generated as you apply for a government service and that is forwarded throughout the process. BundID itself only has a basic user name that you pick yourself and that is not used or stored anywhere outside it. The actual authentication is done via the eID, Elster certificate, etc. which all don’t leave cryptographic traces.

          Don’t get me wrong, this system is still kind of broken. BundID still bundles important information in a central location and urgently needs modernization. And it’s authentication amounts to ‘trust me bro’ from the POV of any other government service. But it does not introduce a global unique identifier either.

      • Helix 🧬@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        24 hours ago

        we don’t have a citizen ID

        OK, so you forgot the Sozialversicherungsnummer and the Steuer-ID?

        • Ontimp@feddit.org
          link
          fedilink
          English
          arrow-up
          3
          ·
          24 hours ago

          They are not really the same though. These are domain specific identities. Sure, the tax office has your tax ID. But your municipality, the state health authorities or the retirement insurance will never ask you your tax ID, don’t have access to it and are not allowed to process it. It’s not a citizen ID that can be used to link different data sets and it’s not saved in the Melderegister.

      • SorteKanin@feddit.dk
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        At least, however, we don’t have a citizen ID such as the one you describe, that could be used to identify people uniquely.

        Oh don’t get me wrong, there is nothing wrong with a citizen ID. Actually a citizen ID is very useful. It should just only be an ID and shouldn’t give any access.

        • Ontimp@feddit.org
          link
          fedilink
          English
          arrow-up
          5
          ·
          23 hours ago

          Depends how much you trust the state. After the Nazi period, the German state is actually not allowed to keep persistent identifiers on people. You can only identify any. given citizen through a domain ID that may not be shared or used beyond a specific domain (e.g tax ID) or a combination of changeable attributes (address, name, etc.).

          In practice this can be annoying, but it’s also a useful precaution to prevent the government form easily pooling and linking information on citizens across domains and levels of state.

  • generator@lemmy.zip
    link
    fedilink
    English
    arrow-up
    21
    ·
    1 day ago

    This is why we need age verification in the EU, so hackers don’t need to attack individual countries.

    But at least the children will feel safe.

    • skvlp@feddit.nl
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 day ago

      Except that underage people (aka children) will be flagged in the data set and thus be easy to search.

      • pmtriste@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        1 day ago

        I think they were being sarcastic, saying the individual countries won’t be hacked because the EU as a whole will be hacked.

  • AItoothbrush@lemmy.zip
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 day ago

    We dont have to worry about a similar thing happening in sweden cause our system is fucked up and everybody already has access to every registered(not even just citizens) persons name, address, phone number, etc.

  • CosmoNova@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    And this is exactly why saving all data about every citizen, including bank transfers and patient records in a single data base is a risk not worth taking. It‘s a terrible idea and simply proposing it already shows you don‘t know anything about keeping data and the people attached to it safe. Everyone knew this would happen. Painful incompetence on so many levels. And so very avoidable if you just didn‘t save it all in one place, under the same user IDs. A surveillance state comes at a terrible cost no matter who the government is at the time. It‘s a bad system.

    • Rothe@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 hours ago

      Bank transfers and patient records weren’t stored in the leaked database though. It was the ID-numbers, names and a physical address which was leaked.

    • ebber@europe.pub
      link
      fedilink
      English
      arrow-up
      3
      ·
      17 hours ago

      The registry includes every single person has lived in Denmark at any point since 1962 or something, that’s the actual reason for the larger numbers

  • emptiness@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    Sounds like they went in through the front door. Great security there. At least one of Denmark’s neighbours provides similar access to companies.

  • trollercoaster@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 day ago

    Wherever there is a feeding trough, the swine will come.

    And a centralised registry of the entire population is a gargantuan feeding trough for data hungry digital swine.