Denmark's Central Person Register Breached; 8.8M Records Exposed
Hackers exploited a company's lawful access to Denmark's CPR system, compromising personal data of 8.8 million citizens—nearly the entire population. The breach indicates a supply-chain attack vector, with the full scope and data types still unclear. This is a significant national security and privacy incident, potentially enabling identity fraud and targeted espionage.
Score Breakdown
Intelligence Tags
Locations
Entities
Part of 2 situations
Denmark CPR System Breach: 8.8M Records Exfiltrated via Third-Party
Denmark's Civil Registration System (CPR) has been compromised, resulting in the exfiltration of personal data for 8.8 million individuals, exceeding the current population. The breach was facilitated through legitimate credentials of a third-party company with authorized access, indicating a supply-chain attack vector. The full scope of data types beyond names, addresses, and CPR numbers, as well as the perpetrator's identity and motivations, remain unclear.