🛡️ Cybersecurity / /via cyberbreaches.org / updated -119m ago

Denmark’s CPR Register Breach Exposes Data on 8.8 Million People

Denmark disclosed that unidentified actors misused a private company’s legitimate access to the national Central Person Register, exposing names, addresses and personal identification numbers for about 8.8 million people. The incident is one of several major breaches listed in early October, alongside attacks affecting DTU, Frontline Education and Fortinet customers. The breach highlights how trusted third-party access can become a route into sensitive public data at national scale.

#CentralPersonRegister#TechnicalUniversityofDenmark#DTU#FrontlineEducation#Fortinet#ShinhanBank#BeeChengHiang
~/ Cybersecurity/ Denmark’s CPR Register Breach Exposes Data on 8...

Denmark has disclosed a breach of its Central Person Register after unidentified actors misused a private company’s legitimate access to the system. The incident exposed the names, addresses and personal identification numbers of about 8.8 million people.

The compromised information is held in Denmark’s national CPR population register. The source timeline describes the incident as an ongoing data breach and does not identify the company whose access was misused or the actors responsible.

The disclosure comes amid a concentrated run of cyber incidents recorded in early October. Denmark’s Technical University said attackers used stolen credentials to breach its DTUBasen identity system, exposing CPR numbers and other personal data belonging to as many as 200,000 current and former users.

Other entries in the timeline show the breadth of the current threat environment. Frontline Education began notifying school districts that a flaw in a third-party product allowed access to employee data, including Social Security numbers, while Fortinet reported that a critical FortiMail vulnerability had been exploited before a patch was available.

Why this matters

The CPR incident demonstrates the scale of harm that can result when attackers abuse legitimate access rather than directly breaking into a central government system. A trusted private connection to sensitive records can provide a powerful path to personal data, making access governance and monitoring as important as perimeter defenses.

The exposed combination of names, addresses and personal identification numbers creates a serious identity-security risk for affected individuals. It also shows why organizations that share or provide access to population data must account for the security of connected companies, credentials and systems.

The wider timeline suggests that supply-chain weaknesses, stolen credentials and exploited vulnerabilities are appearing across public institutions, financial services, education technology and critical infrastructure. The incidents include a suspected AI-assisted attack on South Korea’s Shinhan Bank loan-agent platform and an AI-generated mailing script that exposed email addresses at Singapore’s Bee Cheng Hiang.

Denmark’s investigation remains unresolved in the source material, with the perpetrators unidentified and unauthorized access described as ongoing. Further findings will determine how the company’s legitimate access was abused and what safeguards are needed to prevent similar exposure of national-scale identity data.

share
𝕏 FB
← cd ../news