Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

A massive data breach in Denmark has left millions of citizens vulnerable, after attackers exploited a company account to access sensitive personal information. The incident highlights the critical need for robust cybersecurity measures and emphasizes the importance of protecting sensitive data.

The breach, which was disclosed by Danish authorities on October 6th, involves the unauthorized access of over 8.8 million individuals’ records from the Central Person Registry (CPR) database. This database contains comprehensive information about every citizen in Denmark, including their name, address, date of birth, and other sensitive details. The attackers managed to breach this data through a company account that had been compromised by phishing.

The CPR database is maintained by the Danish Agency for Digitisation (DIGIT), which is responsible for managing various government services, including identity verification and registration processes. The database is used extensively throughout Denmark’s public sector, and its security has now come under intense scrutiny following this breach. According to reports, the attackers exploited a cross-domain privilege escalation vulnerability in a third-party service that provided access to the CPR database.

This type of attack involves exploiting weaknesses in network architecture or configuration to gain elevated privileges within a system, allowing unauthorized access to sensitive data. In this case, the attackers used this vulnerability to map out pathways through various systems and networks, ultimately reaching the CPR database. This breach serves as a stark reminder that even seemingly secure systems can be vulnerable if not properly configured.

The impact of this breach extends far beyond Denmark’s borders, given the interconnected nature of global business and trade. As companies increasingly rely on cloud-based services and third-party vendors for support, the risk of cross-domain attacks grows exponentially. This incident highlights the critical need for robust cybersecurity measures, including regular vulnerability assessments, penetration testing, and employee education programs.

For individuals affected by this breach, it’s essential to remain vigilant and monitor their personal accounts closely for suspicious activity. They should also review their credit reports regularly and consider implementing two-factor authentication on sensitive online services. For organizations handling sensitive data, this incident serves as a stark reminder of the importance of robust cybersecurity measures, including employee education programs, regular vulnerability assessments, and penetration testing.

In conclusion, the Danish government’s warning about the CPR breach emphasizes the critical need for individuals and businesses to prioritize their cybersecurity. With the increasing complexity of network architectures and interconnected systems, it’s more important than ever to stay informed about emerging threats and vulnerabilities. By taking proactive steps to protect sensitive data, we can all play a role in preventing similar breaches from occurring in the future.


Source: The Hacker News — 2026-10-06