hacker-news · Crawled Oct 6, 2026

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Read original article ↗

AI Summary

Unauthorized parties accessed the personal data of approximately 8.8 million individuals in Denmark's Central Person Register (CPR) by exploiting a private company's legitimate access rights. The breach occurred over a 10-day period in September, during which a large volume of automated queries were made to identify valid CPR numbers. The Danish digitalization ministry confirmed the incident, noting that names, addresses, and CPR numbers were exposed, though it remains unclear how attackers gained access to the company's credentials or whether the data was exfiltrated or used. The company's access has since been revoked, and investigations are ongoing by both the data protection authority Datatilsynet and law enforcement.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.