Hackers steal 8 million citizens’ records from Danish government database
- ID
- 31907
- Status
- summarized
- Published
- 05 Oct 2026, 10:58 PM
- Fetched
- 06 Oct 2026, 12:11 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/10/05/hackers-steal-8-million-citizens-records-from-danish-government-database/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 2.5
- Created
- 06 Oct 2026, 12:16 AM
- Tags
- Audience
- developerssaas_foundersdatabase_learners
What happened
Denmark’s Central Person Register (CPR) was breached, with hackers stealing records on about 8 million citizens and residents, including people living abroad and the deceased, from a database that holds about 11 million records. The stolen data includes names, addresses, Danish social security numbers, and other information; the breach happened in September, was discovered on October 2, and was reportedly carried out by abusing a Danish company’s lawful access to search the CPR system.
Why it matters
For most Malaysian developers and founders, this is not an immediate action item: it is a Danish national ID database incident with no stated Malaysia or Southeast Asia impact. If your product integrates identity verification or depends on vendors with privileged access to government identity data, the concrete takeaway is to ask those vendors for query-level audit logs, least-privilege scoping, and breach notification terms, because this incident reportedly came through a company’s lawful access rather than a direct intrusion.
Discussion angle
What due-diligence questions should builders ask identity-verification vendors after a breach caused by a partner’s lawful access, and would those answers change your integration choice?