Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Denmark’s largest health authority, Sundhedsdatastyrelsen, has revealed a shocking data breach that exposed sensitive information of 8.8 million people, including medical records and personal details, after attackers compromised an employee’s company account. The incident highlights the alarming consequences of identity exposure and underscores the need for robust cybersecurity measures to prevent such breaches.

The attackers exploited a vulnerability in the health authority’s system by gaining access to an employee’s company account through social engineering tactics. Once inside, they used their elevated privileges to navigate the system and access sensitive data, including medical records, contact information, and other personal details of nearly 9 million people – roughly half of Denmark’s population. The breach was discovered on September 28, but it’s unclear how long the attackers had been inside the system before detection.

The compromised account allowed the attackers to move freely within the system, accessing various domains and sensitive data without being detected. This type of attack is known as a cross-domain privilege escalation (CDPE), where an attacker gains access to higher levels of privileges within a system by exploiting vulnerabilities in lower-level accounts or permissions. The breach demonstrates how attackers can use social engineering tactics to gain initial access and then exploit existing vulnerabilities to escalate their privileges.

The exposed data includes sensitive medical information, which raises concerns about patient confidentiality and the potential for identity theft. Denmark’s health authority has assured citizens that there is no evidence of misuse, but this incident serves as a stark reminder of the risks associated with data breaches. The attackers’ motivations are unclear at this point, but it’s likely they sought to exploit the sensitive information for financial gain or malicious purposes.

The Danish government has promised to take swift action to strengthen cybersecurity measures and prevent similar incidents in the future. This breach highlights the importance of implementing robust security protocols, including multi-factor authentication, regular system updates, and employee education on social engineering tactics. For individuals affected by this breach, it’s essential to remain vigilant and monitor their accounts for any suspicious activity.

As this incident demonstrates, identity exposure can have far-reaching consequences, making it crucial for organizations to prioritize cybersecurity measures that protect sensitive information from unauthorized access. By being aware of the potential risks and taking proactive steps to secure our digital lives, we can minimize the impact of such breaches and ensure our personal data remains safe.


Source: The Hacker News — 2026-10-06