A hacker broke into the database that holds basically every identifying detail on every person connected to Denmark, living, dead, or long since moved away. Denmark’s digital affairs minister announced it Monday and didn’t soften the language.
The affected database is Denmark’s national population register. It contains names, addresses and CPR numbers, which are similar to Social Security numbers in the US. The registry covers 8.8 million people, even though Denmark has about six million residents, because it also includes people who have died or moved abroad. In total, the database contains around 11 million records.
Christina Egelund, the digital affairs minister, didn’t mince words. She called it “an extremely serious incident,” and said the government is working with every relevant authority to map out how far it actually goes. Translation: they’ve confirmed the break-in, but they genuinely don’t know the full scope yet.
“Together with all the relevant authorities, we are in the process of mapping out the full extent of the incident,” she added.
The ministry said unauthorized people gained access to names, addresses and CPR numbers. In Denmark, CPR numbers are used for many important services, including banking, healthcare and taxes. When combined with a person’s name and address, this data could create a serious risk of identity fraud.
“‘Unauthorised individuals obtained illegal access’ to the names, addresses and CPR, including those who have died or emigrated, the ministry said in a press release, referring to Denmark’s social security numbers.” EuroNews reports.
Authorities have launched an investigation, and as of Monday they had no information on who carried out the attack. What they do know is the entry point: the hackers didn’t breach the government’s systems directly, they went through a Danish company that had legal access to the registry for its own business purposes. Third-party access, breached third party, data gone. It’s the oldest story in this business, and somehow it still works every time.
One detail is especially concerning: the government said the company’s access to the registry has not been revoked. This means the same access used in the attack may still be active. After a breach, one of the first steps should normally be to close the affected access while the investigation continues.
The incident is another reminder that government databases are only as secure as the third parties connected to them. Denmark relies heavily on its CPR system for services such as healthcare, banking and taxes, making this type of data highly valuable not only for identity fraud but also for intelligence and influence operations.
The geopolitical dimension is important. Personal data held by governments can help hostile actors build detailed profiles of citizens, officials, businesses and institutions. In a period of growing tensions between states, such databases can become strategic targets because the information can support espionage, social engineering, disinformation or future cyber operations.
This means a breach of a national population registry is no longer just a privacy or cybercrime issue. It can become a national security problem, especially when the attacker reaches the data through a trusted third party. The incident shows why governments need to treat third-party access as part of their national security perimeter, not simply as a technical or contractual issue.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Denmark)