Full Report
Abuse of private firm's access exposed 8.8M records, including those of people who had died or moved abroad
Analysis Summary
# Incident Report: Abuse of Third-Party Access to Danish Central Population Register (CPR)
## Executive Summary
An unauthorized party exploited the legitimate access credentials of a private firm to compromise Denmark’s Central Population Register (CPR). The breach resulted in the exposure of approximately 8.8 million records, including names, addresses, and national identification numbers. The incident has sparked a national debate regarding the security of the CPR system, as the volume of exposed records exceeds the current living population of Denmark.
## Incident Details
- **Discovery Date:** October 2, 2026
- **Incident Date:** Throughout September 2026
- **Affected Organization:** Central Population Register (CPR) Administration / Ministry of Digitization
- **Sector:** Government / Public Sector
- **Geography:** Denmark and Greenland
## Timeline of Events
### Initial Access
- **Date/Time:** September 2026
- **Vector:** Abuse of Third-Party Privileged Access.
- **Details:** An unauthorized party gained control of or exploited the access rights granted to a "small" unnamed private company that had legal authorization to query the register.
### Lateral Movement
- **Details:** Not applicable in the traditional sense; the attacker utilized existing legitimate API/database access interfaces to perform unauthorized bulk queries.
### Data Exfiltration/Impact
- **Data Stolen:** Names, addresses, and CPR (national identification) numbers.
- **Scope:** 8.8 million records, including deceased individuals, those living abroad, and 55,000 residents of Greenland.
### Detection & Response
- **Discovery:** October 2, 2026. The CPR administration detected "irregular activity" involving a specific company's access credentials.
- **Response Actions:** Immediate revocation of the firm's access; notification to the Danish Data Protection Agency and police.
## Attack Methodology
- **Initial Access:** Valid Account Abuse (Third-party credentials).
- **Persistence:** Continued use of legitimate access tokens/credentials during the month of September.
- **Privilege Escalation:** Not reported; likely abused existing broad read-access permissions.
- **Defense Evasion:** The activity blended in with legitimate business queries until the volume/pattern triggered "irregular activity" alerts.
- **Collection:** Automated querying of the CPR database.
- **Exfiltration:** Data transferred via the legitimate access channel provided to the private firm.
- **Impact:** Massive data breach; potential for identity theft and fraud on a national scale.
## Impact Assessment
- **Financial:** High potential for fraud; costs associated with the proposed re-issuance of CPR numbers for the entire population.
- **Data Breach:** 8.8 million records containing PII (Personally Identifiable Information).
- **Operational:** Critical. The CPR system is the backbone of Danish healthcare, banking, and tax services.
- **Reputational:** High. Public outcry regarding the "broken" nature of using CPR numbers as a primary secret for identification.
## Indicators of Compromise
- **Network indicators:** Irregular traffic patterns originating from the specific private firm’s authorized IP/connection.
- **Behavioral indicators:** A sudden spike in the volume of queries or queries for individuals not previously associated with the firm’s business scope.
## Response Actions
- **Containment:** The CPR administration blocked the unnamed company’s access to the database immediately upon discovery.
- **Eradication:** Investigation launched to ensure no other third-party accounts were compromised.
- **Recovery:** Coordination with the Ministry of Digitization to assess the necessity of changing identification protocols.
## Lessons Learned
- **Third-Party Risk Management:** Providing "broad access" to small private firms creates a massive attack surface for the entire national infrastructure.
- **Authentication Weakness:** Relying on a static identification number (CPR) as a "secret" is insufficient in a digitalized society.
- **Monitoring:** While the breach was detected, it persisted for nearly a month, suggesting a need for real-time anomaly detection for API/database queries.
## Recommendations
- **Implement Zero Trust:** Transition away from CPR numbers as a sole authenticator; move toward multi-factor authentication (MFA) for all services.
- **Least Privilege Access:** Audit all private firms with CPR access to ensure they can only query the specific records required for their legal business functions (narrowing the scope of Section 38(1)).
- **Rate Limiting:** Implement strict rate-limiting and behavior-based alerting on all third-party data portals to prevent bulk exfiltration.