Authorities in Denmark have launched an investigation after unauthorised individuals gained access to the personal information of about 8.8 million people through the country’s Central Person Register (CPR).
The compromised information includes names, addresses and CPR numbers, which serve as personal identification numbers in Denmark. The affected records include people living in Denmark as well as some who have died or moved abroad.
The Danish Ministry of Research, Education and Digitalisation said the breach occurred after unauthorised individuals misused a Danish company’s legitimate access to the CPR system. The company’s access has since been stopped, while the police and relevant authorities investigate the incident.
Denmark’s CPR system contains information on about 11 million registered individuals, including deceased persons and people who have emigrated. Authorities said the names and addresses of people who had registered for name and address protection were not affected by the unauthorised access.
Digitalisation Minister Christina Egelund described the incident as a serious security breach and ordered a comprehensive review of the CPR system. She also urged members of the public to remain vigilant and avoid disclosing passwords or other confidential information to callers or email senders, even if they appear to know personal details about them.
The Danish Data Protection Agency said it had received a report concerning a large number of automated searches of the CPR system and was examining what happened and who may be responsible. Authorities have not yet identified those behind the incident.
