Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
- ID
- 32162
- Status
- summarized
- Published
- 06 Oct 2026, 2:00 PM
- Fetched
- 06 Oct 2026, 3:15 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.0
- Created
- 06 Oct 2026, 3:16 PM
- Tags
- Audience
- developerssaas_founders
What happened
Denmark's digitalization ministry said unauthorized parties accessed names, addresses, and CPR numbers for about 8.8 million people in the national population register, roughly 4 in 5 of the ~11 million people recorded since 1968. The access came not from a breach of the register itself but through a small private Danish company's lawful lookup rights, spanning about 10 days in September 2026 with a very large volume of automated lookups to validate CPR numbers. An employee spotted the anomaly on Friday, October 2; the register's administration cut the company's access and reported the case to Datatilsynet, with police investigating and the 8.8 million figure not yet final.
Why it matters
The attack path was an authorized partner account, not a zero-day — the register's administration only noticed after 10 days of automated lookups, so the real control that failed was anomaly detection on delegated data access, not perimeter security. If you build onboarding, KYC, or any integration that calls a registry or partner API on behalf of users, decide now what volume/burst thresholds and per-account audit logs would have surfaced a 10-day bulk lookup in hours instead of days, and whether you can revoke a single partner's access without a full outage.
Discussion angle
The breach stayed inside the data private companies are legally allowed to receive, and excluded records under name-and-address protection — so what does your monitoring look like for a partner doing only permitted actions, just far too many of them? Walk through what you would actually log and alert on for a high-volume identity lookup integration.