Denmark confirms unauthorized access to the RCP that affected 8.8 million records

Author: Published 5 min de lectura 4 reading

The images in this article were generated with artificial intelligence. How we publish

The Danish government confirmed that for about ten days in September there were unauthorized access to the Central Peru Register (CPR) the national population database. According to the ministry responsible for digitization, the intrusions allowed to consult the names, addresses and personal identification numbers (PCR) of approximately 8.8 million records - a universe that includes living, dead and people who have emigrated -, which is equivalent to about four in five entries of the record, which contains a total of about 11 million inscriptions. The authorities have suspended access to the private company for which the consultations were channelled and have reported the incident to the Danish Data Protection Agency ( Datatilsynet) and the police.

Facts confirmed: The administration of the register detected unusual activity on 2 October; access was made through a small Danish company that had the legal right to request data from the RCP; the episode lasted about 10 days; mass consultations were notified to Datatilsynet; the ministry has indicated that data from persons with name and address protection were not accessed; the figure of 8.8 million is that reported by the ministry but is not yet final.

Denmark confirms unauthorized access to the RCP that affected 8.8 million records
Image generated with IA.

What technically allowed access. Danish law allows certain companies to request RCP data on persons who have already identified in specific transactions. The RCP is a 10-digit number (six of the date of birth and four serial) and, by its structure, can be subject to automated enumeration if the date of birth is known. Datatilsynet noted that "a large number" of automated consultations were conducted to identify valid CPR numbers; however, there is no public confirmation of the exact technique used or whether the attackers systematically went through possible combinations by date of birth. This lack of precision is key: the precise way in which the list was obtained (breach of the intermediary undertaking, abuse of the authorized service, committed credentials, or exploitation of lack of controls in the supplier) is not yet verified.

What is yet to be determined. There is no public evidence, for now, about whether the data were copied and retained by the intruders or whether they were used in fraud already occurred. Nor has it been clarified whether the RCP of persons with active protection was accessed (the Ministry states that no names and addresses of those with protection were included, but does not say whether their RCP numbers were exposed). Nor is the identity of the actors that caused access or the initial vector known - even though the police investigation and the investigation of Datatilsynet are under way to answer exactly those questions.

The specific risks associated with the exposure of names, addresses and CPR numbers are real and measurable: they allow speed and SIM-swap more credible, facilitate the creation of synthetic identities or supplanting to suppliers who accept the RCP as a partial identity tester, and can accelerate credit fraud or request for services on a non-proprietary basis. Although the CPR number should not be the only identity test according to the record's own guide, its possession reduces friction for well-prepared attackers. In addition, if the attackers correlate this data with other public leaks or with database purchases, the risk of fraud increases.

The authorities have published practical measures and assistance channels: the Ministry refers to the Danish government's security council website and the Cyberhotline telephone line. In Denmark it is recommended to activate a credit warning marker in borger.dk that it warns companies when an attempt is made to grant credit to a holder and requires more comprehensive identity checks - although this protection may take days to spread to external systems.

What citizens can and must do. First, assume that exposure increases the likelihood of targeted fraud attempts and raises suspicion of unexpected communications.

Immediate and verifiable concrete: do not share MitID / NemID codes or passwords; do not click on unsolicited messages and check URLs on the browser bar; call directly to the mail or SMS issuing company to verify authenticity; activate a credit warning marker on borger.dk if it is resident in Denmark; and contact banks and financial institutions to request additional surveillance on unusual operations. Use the government Cyberhotline for immediate support (+ 45 33 37 00 37), which has temporarily extended its care hours.

On a technical level, it is appropriate to change relevant passwords and to review access related to services using MitID; to activate any second-factor authentication that does not depend exclusively on SMS (authentication applications or physical keys) and to monitor bank extracts and credit notifications. For companies and professionals: review access logs, audit third party permits, require strong authentication for services that consult records and limit the ability to consult mass lists through rate limiting and alerts that trigger automatic blockages when atypical query patterns are detected.

Denmark confirms unauthorized access to the RCP that affected 8.8 million records
Image generated with IA.

Regulatory consequences and possible structural solutions. Datatilsynet has initiated an investigation to examine the adequacy of the organisation and security measures in the supplier and in the administration of the register. The Ministry has ordered a security review. These investigations may result in sanctions, policy changes on which operators can consult and under what conditions, and the obligation to introduce additional technical controls (registration and verification of consultations, fee limits, enhanced authentication, real-time monitoring and mandatory third-party audit).

Finally, there are two relevant political uncertainties: whether the extent of the filtration will force the massive reallocation of CPR numbers (the law allows for the change of numbers in cases of abuse, but this process is exceptional and involves costs and complications) and whether individual notification will be required of the people concerned. For now, the authorities have pointed out that this decision is pending investigation.

To follow the case and obtain official recommendations, please consult the Danish Data Protection Agency at datatilsync. and official population statistics Statistics Denmark. Stay alert, activate the available protection measures and expect further instructions from the authorities if it turns out that you are among those affected.

Coverage

Related

More news on the same subject.