Edited by humans. Written by AI. How our editing works
All articles

Denmark's CPR Breach Tests Access and Identity Rules

Denmark's CPR breach exposed data on 8.8 million registered people. Lawful access, registry query controls and identity checks point to different remedies.

Rachel "Rach" Kovacs

Written by AI. Rachel "Rach" Kovacs

October 7, 20266 min read
Share:
Denmark's CPR Breach Tests Access and Identity Rules

Denmark's Central Population Register breach exposed personal information associated with approximately 8.8 million registered people after an unauthorized party misused a private company's legitimate access. Names, addresses and CPR identification numbers were among the data obtained. The register's administrators learned on October 2 of irregular activity during September and established the scale of the incident over the following weekend. They blocked the company's access, and police are investigating.

The word legitimate describes the company's permission to use the register. It says nothing about the person who misused that permission. That is the security problem Denmark now has to examine: a private user can have a lawful reason to retrieve some records, while the same route into the system can expose far more if its limits fail or are circumvented. How the unauthorized party gained control of the company's access remains unclear.

The scale also needs careful reading. CPR holds information on roughly 11 million registered people, including people who have moved abroad or died. Denmark's current population is around 6 million. So the figure of 8.8 million refers to affected people in the register, rather than 8.8 million current residents. It also does not describe one uniform set of living people facing the same immediate risk.

A Register Built for Use

Established in 1968, CPR contains records of residents, emigrants and deceased people. Its numbers are used across public services and everyday transactions. That history helps explain why the register's count exceeds Denmark's current population; its use across services explains why access to it warrants scrutiny. The age of the register does not explain how this intrusion worked.

The register also includes more than 55,000 people living in Greenland who use CPR numbers for healthcare, tax services and banking. Those uses illustrate a design tension. An identifier that works across settings is convenient precisely because the same person can be recognized across them. When a number and associated personal details leave the register, the consequences can follow a person across settings too. The breach figure alone cannot tell any individual which records about them were accessed or how someone might try to use those details.

Private access is part of CPR's intended operation. Under the rules described for section 38(1) of Denmark's Civil Registration System Act, eligible private recipients can obtain data about a defined group of people identified individually in advance. They must also be legally entitled to process the information under data protection law. A business that needs to identify particular people may therefore have a lawful reason to ask the register about them. Eliminating every private query would change that service, as well as its exposure to misuse.

But a rule limiting who should be queried raises a separate operational question: what prevented, or should have prevented, one company's access from being used to retrieve data on millions of records? The Danish Data Protection Agency says the attack involved brute-force enumeration of valid CPR numbers followed by extraction of related data. That method makes query volume and patterns obvious subjects for investigators. It does not, by itself, identify how the company's access was taken over or which safeguards were in place at the time.

A useful review would ask how a recipient's permitted group of people was represented in the system, whether the register checked each request against that scope, and when unusual request patterns became visible to administrators. Those questions also put responsibility in the right places. An individual whose number appears in CPR cannot set the register's query limits; the register's operators and its authorized users can examine how access is granted, used and monitored. A legal condition on a company's use of data and a system control that checks each request serve different purposes. The investigation can examine both without assuming, from the scale alone, which one failed.

What Would a New Number Fix?

One proposed response is to issue new CPR numbers. Digitization minister Christina Egelund said in a TV interview that it was too soon to decide whether Denmark would issue new CPR numbers. The appeal is understandable: if a number has been exposed, replacing it might appear to restore some privacy around that identifier. The difficulty is that a new identifier can be entered into systems that use it, shared with authorized recipients and exposed through the same access route unless that route changes.

Danish cybersecurity specialist Jan Kaastrup argued to TV 2 that a CPR number alone should not be accepted as proof of identity. His proposal tackles a different point in the chain. An identifier answers which record? Authentication answers is this person entitled to act as the person named in that record? A service that accepts the number alone as proof of identity gives someone who learns it a use for the stolen data. A service that checks identity separately can reduce that opportunity, though stronger checks would not undo the loss of names, addresses or numbers already retrieved.

These approaches can be compared by the failure each addresses. Reissuing numbers responds to exposure of existing identifiers. Changing verification practice responds to what a person can accomplish with an exposed identifier. Restricting and monitoring registry queries responds to how so many records could be accessed through a private connection. Treating them as interchangeable would leave at least one question unanswered.

There is also a narrower boundary within the breach. The ministry said people who had registered for name and address protection did not have those names and addresses exposed. Whether other information connected to those people was accessed remains unclear. For anyone assessing their own exposure, which data was protected is a more useful question than a simple affected-or-unaffected label.

For people concerned about their own information, one practical risk is an unsolicited caller or message that sounds convincing because it contains a correct name, address or CPR number. The CPR administration has warned people not to disclose passwords or other confidential information in response to calls or messages, even when the sender knows those details. If someone claims to represent an organization you use, end the exchange and contact that organization through a channel you find yourself. Recognizable personal information in a message is a reason to check the sender, not a substitute for checking.

The company connection explains how the investigation began; it should not become the whole answer. Denmark can determine what happened at that connection while also asking what a legitimate connection was allowed to retrieve, how rapidly misuse could be detected and which services would accept the exposed numbers as proof of a person's identity. Each question tests a different boundary. A replacement number addresses only one of them.

More Like This