CPR data for 8.8 million Danes leaked – can be used for phishing and identity theft

Unauthorised individuals have gained access to names, addresses and CPR numbers of 8.8 million citizens. A cybersecurity professor warns of targeted phishing attacks.

CPR data for 8.8 million Danes leaked – can be used for phishing and identity theft

Cybersecurity expert: Leaked CPR data opens door to credible fraud emails

Unauthorised individuals have gained access to names, addresses and CPR numbers of approximately 8.8 million citizens registered in the Danish CPR system. The Ministry of Research, Education and Digitalisation announced this on Monday, according to B.T.

The CPR system encompasses both living, emigrated and deceased persons.

Jens Myrup Pedersen, professor of cybersecurity at Aarhus University, explains that the information can be used to make phishing attacks significantly more convincing.

– You can send very authentic-looking emails and text messages that appear to come from authorities, not least because they contain CPR numbers, or because you know their date of birth, he says.

– So the more data you have about people, the more authentic attacks you can also carry out, adds Pedersen.

However, he assesses that the leaked information is unlikely to be sufficient for, for example, taking out a loan in someone else's name.

– In any case, as a provider of such services, you cannot say that just because you have a CPR number, you also know who the person is, says Pedersen.

Nevertheless, the professor points out that the data can be misused for other forms of identity theft. As an example, he mentions a situation where someone is stopped by police or checked on a train without a valid ticket.

– Then they would certainly get a lot from those details, says Jens Myrup Pedersen.

He also emphasises that data such as name, address and CPR number could potentially be sold on to third parties and combined with publicly available information or images.

Source: B.T.

Read this article in the original language