Local Chorus
Local news from local sources, read in your language.
Settled
Verified

Denmark says 8.8 million CPR records accessed in national ID register breach

🇯🇵 Japan 15:01 IT & software Tech2 Official updated 3 d ago first reported by ITmedia

In short

Denmark's digitalisation ministry said on 5 October that a third party obtained the names, addresses and personal (CPR) numbers of about 8.8 million people from the central CPR personal register. Authorities say the access came through a Danish company that held legitimate lookup rights rather than a direct intrusion into the register. The ministry says it cannot yet say who was behind it, and police are investigating.

Read the full story 2 min read

Denmark's digitalisation ministry announced on 5 October that a third party had gained access to the names, addresses and personal identification (CPR) numbers of about 8.8 million people held in the central personal register, CPR. NHK reported that police are investigating the unauthorised access. ASCII.jp described the CPR number as Denmark's equivalent of Japan's My Number, used for identity checks in administration, banking and healthcare. [ 1 , 2 , 3 ]

According to both the technology outlets, the incident was not a direct intrusion into the CPR system. Instead, access held by a Danish company with legitimate authority to look up the register was misused by a third party. Authorities said large numbers of automated searches were run for the purpose of identifying valid CPR numbers. The ministry said the data obtained was limited to what the private company could view, and that the authority has stopped the company's access and reported the matter to the data protection authority. [ 1 , 2 ]

The register holds about 11 million records, a figure that includes people who have died or moved abroad, and the roughly 8.8 million affected records amount to about 80 percent of the total. Because CPR also covers deceased and emigrated people, the affected number is larger than Denmark's population of about 6 million. People who use a scheme that keeps their names and addresses undisclosed were not affected, the outlets reported. [ 1 , 2 , 3 ]

The CPR management authority learned on the evening of 2 October of suspicious activity on the system during September, and an investigation over the weekend established that about 8.8 million records had been accessed, according to ITmedia. The ministry's responsible minister called it “an extremely serious incident”, said it had been reported to a parliamentary committee, and said the authorities were working with the relevant agencies to establish the full picture. The ministry said preventive measures had been started and a full security review of the CPR system requested. It added that it could not yet say who was behind the access. [ 2 ]

The government urged residents not to trust someone simply because that person knows their name, address and CPR number. NHK reported the disclosure as a case of unauthorised access to Danish government data affecting more records than the country's population, with police investigating. [ 1 , 3 ]

Why it matters

The CPR number is used for identification in public administration, banking and healthcare in Denmark, so the exposure of names, addresses and numbers for roughly 80 percent of all registered records raises the risk of identity misuse. The government has told people not to trust anyone simply because that person knows their name, address and CPR number. The ministry has also ordered a full security review of the register, indicating the incident may lead to changes in how outside access to CPR is granted.

Key facts

  • Denmark's ministry responsible for digitalisation announced on 5 October that a third party had accessed about 8.8 million people's records in the CPR central personal register. [ 1 , 2 ]
  • The accessed data included names, addresses and CPR numbers. [ 1 , 2 ]
  • Authorities say the access was not a direct intrusion into the CPR system but misuse of a Danish company's legitimate inquiry access. [ 1 , 2 ]
  • CPR holds about 11 million records, including deceased people and people who moved abroad, and the roughly 8.8 million affected records are about 80 percent of that total. [ 1 , 2 ]
  • The affected figure exceeds Denmark's population of about 6 million because the register also keeps data on deceased and emigrated people. [ 2 , 3 ]
  • People who use a scheme to keep their names and addresses undisclosed were not among those affected. [ 1 , 2 ]
  • The ministry says it cannot say at this stage who carried out the access, and police are investigating with the relevant agencies. [ 2 , 3 ]

Confirmed by several sources

  • Danish authorities announced that the names, addresses and CPR numbers of about 8.8 million people were accessed in the central CPR register. [ 1 , 2 , 3 ]
  • The number of affected records exceeds Denmark's population because CPR also stores data on deceased people and people who moved abroad. [ 1 , 2 , 3 ]
  • The access was not a direct intrusion into the CPR system but misuse of access held by a Danish company with legitimate lookup rights. [ 1 , 2 ]
  • Danish police are investigating the incident, according to the ministry. [ 2 , 3 ]

Still unclear

  • Who carried out the access, and whether they are an individual, group or state actor. The ministry said in document 2 that it is not at a stage where it can say who the attacker is.
  • Which Danish company's legitimate access was abused. Neither document that describes the mechanism names the company.
  • The ministry has begun preventive measures and asked for a full security review of the CPR system. Reported by a single source so far

What local media are saying

Technology mediaThe two technology outlets focused on the mechanism and scale of the incident, stressing that this was misuse of a legitimate company's lookup access rather than a breach of the CPR system itself, and setting out the 8.8 million figure against the register's roughly 11 million records. Both explained CPR as Denmark's equivalent of Japan's My Number, and highlighted the government warning not to trust anyone who already knows your name, address and CPR number. [ 1 , 2 ]
Official sourcesNHK framed the incident around its scale, reporting that unauthorised access affected about 8.8 million people's names and personal identification numbers, more than the country's population, and that police are investigating. It gave no technical detail on how the access occurred. [ 3 ]

Timeline, local time

  1. The CPR management authority learns of suspicious activity on the system that took place during September. [ 2 ]
  2. The Danish digitalisation ministry announces the security incident and the scale of the accessed data. [ 1 , 2 ]
  3. ASCII.jp reports the incident, including the government's warning to residents. [ 1 ]
  4. ITmedia reports the ministry's account, the suspension of the company's access and the referral to the data protection authority. [ 2 ]
  5. NHK reports that police are investigating the unauthorised access. [ 3 ]