{"id":9929,"date":"2026-10-07T12:32:16","date_gmt":"2026-10-07T12:32:16","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9929"},"modified":"2026-10-07T12:32:16","modified_gmt":"2026-10-07T12:32:16","slug":"denmarks-national-id-system-breach-exposes-personal-data-of-8-8m","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9929","title":{"rendered":"Denmark\u2019s national ID system breach exposes personal data of 8.8M"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Denmark is reviewing security controls around its national citizen registry after unauthorized parties exploited a company\u2019s access credentials to harvest records on approximately 8.8 million people over a 10-day period. The breach covers people living in Denmark as well as individuals who have died or moved abroad, while people with protected names and addresses were not affected.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/ufm.dk\/aktuelt\/pressemeddelelser\/2026\/oktober\/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger\/\" target=\"_blank\" rel=\"noopener\">The unauthorized activity<\/a> took place for about 10 days in September and was discovered on October 2 after CPR administrators noticed unusual activity. Authorities subsequently found that <a href=\"https:\/\/nyheder.tv2.dk\/live\/samfund\/2026-10-05-uvedkommende-har-faaet-adgang-til-88-millioner-cpr-numre\" target=\"_blank\" rel=\"noopener\">more than 14 million<\/a> searches had been made through the company\u2019s account, with about 8.8 million returning records.<\/p>\n<p class=\"wp-block-paragraph\">The affected company has since been cut off from the CPR system, while Denmark\u2019s National Special Crime Unit is investigating. Authorities have not identified those responsible, but officials have warned that the exposed CPR numbers could enable fraud and identity-related abuse.<\/p>\n<p class=\"wp-block-paragraph\">The incident is also forcing Denmark to reconsider how CPR numbers are used for identity verification. Officials are <a href=\"https:\/\/admin.sikkerdigital.dk\/virksomhed\/uvedkommende-har-faaet-adgang-til-borgeres-cpr-oplysninger-saadan-kan-du-verificere-borgere-der-tager-kontakt-til-jer\" target=\"_blank\" rel=\"noopener\">advising<\/a> organizations not to rely on a CPR number alone and to use stronger mechanisms such as MitID, <a href=\"https:\/\/www.csoonline.com\/article\/563753\/two-factor-authentication-2fa-explained.html\">two-factor authentication<\/a>, or one-time codes.<\/p>\n<p class=\"wp-block-paragraph\">A broader security review of the CPR system is now underway.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Denmark is reviewing security controls around its national citizen registry after unauthorized parties exploited a company\u2019s access credentials to harvest records on approximately 8.8 million people over a 10-day period. The breach covers people living in Denmark as well as individuals who have died or moved abroad, while people with protected names and addresses were [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9930,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9929","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9929"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9929"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9929\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9930"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}