Forgot your password?
typodupeerror
Privacy Security

Hackers Steal 8 Million Citizens' Records From Danish Government Database (techcrunch.com) 18

Hackers stole records belonging to roughly 8 million Danish citizens and residents from Denmark's Central Person Register (CPR), including names, addresses, social security numbers and other personal information. The breach is believed to be the largest in Denmark's history. TechCrunch reports: The CPR is a government database of Danish citizens' information, including their government-issued identity number for paying taxes and accessing other services. Denmark's current population is about 6 million people, but the database includes records for about 11 million people, with some of the data going back decades.

The Danish government would not say who is behind the breach, which happened in September but was discovered on October 2. However, it said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." (Some companies in Denmark have access to the CPR for verifying people's information with the government.)

Hackers Steal 8 Million Citizens' Records From Danish Government Database

Comments Filter:
  • The only way to stop constant breaches is to disincentive stealing the data in the first place.

    Perhaps someone will come up with a new privacy paradigm one day where all our data is public by design but you can't do anything malicious with it even if you have it.

    You'd probably have to confirm all state-altering operations either in person or via some sort of an individual-bound, undisputable cryptographic signature but I'm sure it'd be worth the effort.

    Small steps. Let's start with prohibiting sending scans

    • by pjt33 ( 739471 )

      There are use cases you're not covering. Last month I needed a photo of my sister-in-law's ID card to prove that I'd correctly transcribed her address (bureaucrats don't always understand that other countries do things like addresses differently) when applying for a document to make it easier for her to visit. If she'd had to be there in person we'd have had a circular dependency.

  • There are 8 million Danes.
    • And I learned they have a social security program with unique numbers the hackers can steal. Is theirs also funded by currently working individuals paying for seniors like in the US?

      • Re:Today I learned (Score:4, Interesting)

        by Quantum gravity ( 2576857 ) on Tuesday October 06, 2026 @03:42AM (#66364900)
        Denmark's population is just over 6 million.

        Many countries like Denmark, Sweden, Norway, and Finland, all have personal identification number, based on date of birth. It is fairly similar to the American Social Security Number but that does not require citizenship.

        There are also countries that lack some form of personal identification number, such as Australia, New Zealand, and the United Kingdom. In Germany, it is illegal to have a single number that links all systems, which forces them to use different numbers for the same individual.
        • by Teun ( 17872 )
          Yep, a good 6 million Danes are alive.
          Maybe they can add a good 50.000 from Greenland but that's it, the rest are dead.
          Presently I'm in Denmark and the Danes have a great trust in their government, now they suddenly realize their borders don't stop this kind of shit.
          A few years ago the GF needed a type of sleeping pill which her job was not allowing, the doctor just booked it on the CPR number of her deceased mother...
          • by Rei ( 128717 )

            A few years ago the GF needed a type of sleeping pill which her job was not allowing, the doctor just booked it on the CPR number of her deceased mother...

            That's a sign of a dysfunctional system, not a functional one.

        • by Rei ( 128717 )

          I assume that Denmark's system is similar to our kennitala ID system. The big difference between a kennitala and a social security number is that a SSN is both an key and a password, while a kennitala is purely a key. Kennitölur are public. You can't "do anything" just by having someone's kennitala. Combining both a key and password into a single number is insane from a security perspective, IMHO.

          Anyway, this headine would have been more fun if the words were rearranged:

          Database Records: Citizens' H

      • You aren't paying for seniors. You are partying the government to replace the money the government stole from seniors.
  • The hacking has increased their population by almost 2 million.

  • AI agents are called "hackers" now?
    • by dutt ( 738848 )

      What would separate the AI agents hacking from a person hacking and performing the same set of actions?

      It's hacking all the same.

  • by TechyImmigrant ( 175943 ) on Tuesday October 06, 2026 @05:39AM (#66364994) Homepage Journal

    From TFS: "Some companies in Denmark have access to the CPR for verifying people's information with the government"

    So the people's data was being used as an authentication token.

    That is as bad a design as you could possibly come up with.

  • by spyfrog ( 552673 ) on Tuesday October 06, 2026 @11:08AM (#66365296) Homepage
    I livein Sweden. My personal identity number "leaked" the second I was born - they are public information... you can't really use them for anything

You have a tendency to feel you are superior to most computers.

Working...