CPR database breach exposes personal information of 8.8 million Danes

Unauthorised parties gained access to names, addresses and CPR numbers of 8.8 million registered individuals. The case is now being investigated by police and the Data Protection Agency.

CPR database breach exposes personal information of 8.8 million Danes

Massive security breach in the Central Civil Register

Unauthorised parties gained access in September to personal information associated with approximately 8.8 million people in Denmark by misusing a company's legitimate access to the Central Civil Register (CPR). The authorities announced this on Monday, according to The Copenhagen Post.

The compromised information includes names, addresses and CPR numbers as well as other data stored in the system, according to the Ministry of Research, Education and Digitalisation.

The CPR administration has described the incident as a "serious security breach."

Minister briefed Parliament

"This is a deeply serious incident, which is why I have also briefed the Parliamentary Committee on Business and Digitalisation about it," said Research, Education and Digitalisation Minister Christina Egelund.

"Together with all relevant authorities, we are working to map the full extent of the incident."

The ministry states that the unauthorised parties exploited a Danish company's legitimate search access to the CPR system. The CPR administration subsequently blocked the company's access.

The breach occurred during September. The CPR administration became aware of the matter on Friday evening of the previous week.

8.8 million of 11 million registered individuals affected

The CPR system currently contains registrations for approximately 11 million people — a figure that includes current residents of Denmark as well as deceased and emigrated individuals. Of these, 8.8 million were affected by the unauthorised access.

In addition to names, addresses and CPR numbers, the register can contain information on marital status, birth registration, family relations, affiliation with the Danish National Church and information on guardianship. The ministry has not yet specified precisely which additional information was accessed in individual cases.

According to the review carried out so far, names and addresses of individuals with name and address protection have not been exposed.

Measures introduced to prevent recurrence

Egelund stated that measures have already been introduced to reduce the risk of similar incidents.

"We have already launched initiatives in relation to the CPR which are intended to prevent similar incidents," she said.

"Furthermore, I have requested that a comprehensive security review of the CPR system be conducted."

The CPR administration is now working together with specialists and other authorities to establish precisely what has happened and the full extent of the breach.

Police investigating — Data Protection Agency handling the case

The case has been reported to the Data Protection Agency and is under investigation by police.

The Data Protection Agency stated on Monday that it received notification of the incident from the CPR register on Sunday.

"Since the case has only just been received and is still being handled, the Data Protection Agency does not at this time have the ability to assess the specific circumstances or comment further on the case," the agency stated.

Egelund urged citizens of Denmark to remain vigilant in the coming period and follow official digital security guidance.

Source: The Copenhagen Post

Read this article in the original language