Denmark’s Central Population Register (CPR) says a breach exposed personal data for about 8.8 million registered individuals, including names, addresses, and CPR numbers. The incident involved brute-forcing valid CPR numbers through a private Danish company’s legitimate access, and authorities have blocked the access and launched an investigation. #CentralPopulationRegister #CPR #ChristinaEgelund
Keypoints
- The CPR breach exposed data belonging to about 8.8 million people.
- Exposed information included names, addresses, and CPR identification numbers.
- Attackers used a private Danish company’s legitimate access to query the registry.
- The Danish Data Protection Agency said brute-forcing was used to enumerate valid CPR numbers.
- Authorities blocked the company’s access, launched an investigation, and urged citizens to stay alert.