Unknown intruders have used a private company’s legitimate login to search Denmark’s central population register and have reached the records of about 8.8 million people, the Danish Government has said.
The register holds about 11 million entries, including the dead and those who have left the country.
The Ministry of Research, Education and Digitalisation said on October 5 that the exposed data include names, addresses and CPR numbers, the Danish personal identification number, for living and deceased people as well as for those who have moved abroad.
The ministry said those three fields had been copied, not merely viewed.
Records marked as specially protected, used for people at risk of violence or harassment, were not included.
The register can also hold marital status, birth details, family links, affiliation to the Church of Denmark and notes on legal incapacity.
The ministry has not said how much of that wider set was opened.
The CPR administration noticed an anomaly on the evening of October 2.
The misuse ran during September, through a Danish firm’s lawful right to query the system.
That access has since been blocked, and the administration has ended the arrangement with the company.
The case was reported to the Danish Data Protection Agency, Datatilsynet, on October 4 and passed to the police. No suspect has been named, and the ministry has given no motive.
Christina Egelund, the minister for research, education and digitalisation, called it “a deeply serious incident” and said she had briefed the business and digitalisation committee of the Folketing, Denmark’s parliament.
“Together with all relevant authorities, we are in the process of mapping the full extent of the incident,” she said.
She added that she had ordered a full security review of the register.
Citizens have been told to watch for fraud. The ministry said they should never hand over passwords or confidential details by telephone or email and pointed them to the State-run advice site sikkerdigital.dk, with the national cyber hotline staffed from 8am to midnight.
A CPR number is the key to tax, health and banking in Denmark, so a name, an address and that number are enough for impersonation even if no medical or financial files were taken.
Jens Myrup Pedersen, professor of cyber security at Aalborg University, said the clearest danger was convincing phishing, with messages that carry correct personal details and appear to come from a bank or a public authority.
Denmark’s population is about six million. The 8.8 million figure is larger because the register keeps people who have died or moved abroad.
The breach is unusual less for its method than for its coverage: A supplier login, not a break-in, reached most of the historical population file.
Government registers have been taken before, usually with worse consequences once the data left the building.
In 2017 WannaCry shut down parts of the National Health Service in England.
Ireland’s health service was knocked offline for weeks by a ransomware attack in 2021.
Costa Rica declared a national emergency in 2022 after the Conti group encrypted government systems.
In 2023 the UK’s Electoral Commission disclosed that hackers had had access to its email and the electoral registers for more than a year.
Between May and August this year a hacker calling himself ZeroBytes took tax files from the French public-finances directorate, the DGFiP. The haul included contact data, reference income and withholding rates for about 353,000 individuals and 252,000 firms, along with cadastral records later put at 1.8 million files, taken using stolen passwords and a compromised surveyor’s login.
France’s national cyber security agency ANSSI said in a September report that the intrusion needed no unusual tools, listing absent multi-factor authentication, passwords below standard and work accounts used from personal devices. The French Government apologised to roughly 700,000 taxpayers.
A claimed leak of an interior ministry staff directory, mostly gendarmes, has not been confirmed.
European Union law has tightened around this kind of failure. The General Data Protection Regulation gives data controllers 72 hours to report a breach to their supervisory authority, and the NIS2 directive, which member states were due to write into national law by October 2024, extends security and reporting duties to public administration.
Member states are also due to offer citizens a certified EU digital identity wallet by the end of this year under the revised eIDAS regulation, a scheme built on the same national identity numbers now in circulation in Denmark.
Governments are still expanding the data they hold. Digital identity schemes, centralised tax and health records, and mandatory online filing all increase what a single compromised login can expose.
Officials regularly warn of Russian, Chinese and criminal hacking groups, though the security infrastructure has not kept pace with the volume of data now held in one place.
The hack left workers in the affected ministries without access to a variety of services, including email, on their mobile phones. https://t.co/pZsyJi4oX8
— Brussels Signal (@brusselssignal) July 25, 2023