What happened?
The digital affairs ministry has announced that hackers broke into Denmark's national registry (CPR) and gained access to personal information on 8.8 million people, including those who have died or emigrated.
By abusing a Danish company's legal access to the CPR system, unauthorised individuals managed to obtain illegal access to the names, addresses, and CPR numbers of millions of people.
The situation has been described as “possibly the biggest security breach ever” by cyber security professor at Aarhus University, Jens Myrup Pedersen.
The unauthorised individuals had access to CPR details for 10 days in September.
Who is affected?
If you have looked at the number 8.8 million and thought, “but Denmark’s population is only 6 million!” you are not alone.
The administration of the national registry has approximately 11 million registered individuals, which includes people who are currently alive and residing in Denmark, but also deceased individuals and individuals who have moved abroad.
Today’s registry includes information about everyone ever registered in today’s national registry, which was established on April 2nd 1968.
Faroese residents aren’t included in the CPR registry, but residents of Greenland have been since 1972.
What details have been compromised?
The administration of the national registry (CPR), which other than distributing social security numbers (CPR numbers) to newborns and newcomers, also stores information about everyone who lives or has lived in Denmark.
This includes
- CPR number
- Name and address
- Marital status
- Registration details related to birth, e.g. details about place of birth
- Details about citizenship
- Family relationship (details about parents and children)
- Relationship to The Church of Denmark (whether you’re a member, not a member, or have been a member)
- Details about legal incapacity and protection. This can include name- and address protection.
What are the next steps?
The Danish police are investigating the case and have some prior experience to similar, but less serious, situations.
A year ago the police investigated a case where an intern had abused his legal access to the CPR registry, by selling details to the gang environment.
The police have access to the CPR registry’s security log, which is stored for six months. The security log gives details about what company has made searches within the registry.
The CPR registry can also restore deleted data from the security log.
The security log will therefore give the police details about which unauthorised individual has accessed the CPR registry.
As the data breach has quite precisely been pinpointed, it shouldn’t take the police long to determine who is responsible for the hack.
A journalist at Danish news outlet, TV2, asked Minister for Science, Higher Education and Digital Affairs, Christina Egelund, whether we will be given new CPR numbers. To this she answered that it was still too early to tell.
What should I do now?
Be particularly vigilant in the coming months, as the obtained details can be used for targeted phishing attempts. Make sure to never give out passwords or other confidential information in connection with telephone inquiries, or inquiries via e-mails, even if the recipient knows your name, address and CPR number.
The digital affairs ministry has published the following tips for avoiding scams and phishing.
1. Be extra aware of unsolicited contact
Be particularly aware of text messages, calls and emails where the sender has information about you which you don’t remember sharing.
2. Don’t click any suspicious links
If you receive unsolicited text messages or emails with links, then don’t click them. Instead access the website they claim to be sending from directly from your browser or call the sender’s phone number to double check.
3. Don’t share any details.
Never share information from your MitID, two-factor codes, passwords or credit card details.
4. Set up a credit alert on borger.dk.
A credit alert marks your CPR details, making it more difficult to set up a loan in your name. You can find a step-by-step guide to setting up a credit alert here.
READ ALSO: How to deal with scammers in Denmark
Comments