Security

Denmark found an 8.8 million record breach on an invoice, not an alarm

(today) · 3 min read · By Future Technology · Edited by Nath Connell

Key takeaways

  • Attackers misused a small company's legitimate CPR access for about ten days in September and retrieved records on 8.8 million people.
  • The account made more than 14 million lookups; the data was mainly names, addresses and CPR numbers.
  • No security alert fired. A very large per-lookup invoice is what flagged the activity.
  • Around 970,000 Danes had registered a credit warning by 7 October, up from just under 250,000 on 1 October.

Nobody hacked Denmark's Central Person Register. Somebody logged in.

For roughly ten days in September, attackers used a small Danish company's legitimate access to the CPR register, the national database behind almost every interaction a Dane has with the state, their bank or their doctor. According to officials quoted by SecurityWeek, the account fired off more than 14 million lookups, and 8.8 million of them returned a record. Denmark has about six million living residents, so the haul almost certainly includes people who have died or moved abroad as well.

What was taken

Mainly names, addresses and CPR numbers. That last one is the problem. A CPR number is a ten-digit identifier built from your date of birth, and it works as a key across Danish public and private services. People who had registered for name and address protection were not affected, according to the national registrar.

The company has not been named. Its access has been cut off and police are investigating. Nobody has said who was behind it or what the data was for, though the Agency for Public Security has flagged digital fraud as a possible motive.

The alarm was the bill

Here is the bit that should worry every security team reading this. Companies pay per CPR lookup. When the monthly invoicing ran, the bill was, in the words of officials reported by The Copenhagen Post, very, very large. That is what tipped them off.

Not anomaly detection. Not a rate limit. Not a fraud model. An accounts team looking at a number that made no sense.

Fourteen million queries from one small business account over ten days is about 16 lookups a second, every second. Any sensible rate limit on a per-customer API would have tripped long before the data was gone. This is a textbook third-party access failure: the system trusted the credential, and the credential belonged to someone who should never have needed more than a few hundred lookups a day.

What happens next

Digitalisation Minister Christina Egelund has ordered a security review of the whole register and has not ruled out issuing new CPR numbers, which would be a huge undertaking for a system that underpins everything from tax to healthcare.

Danes are not waiting. The Digital Affairs Ministry says around 970,000 people had placed a credit warning by 7 October, up from just under 250,000 a week earlier.

The lesson for everyone else

You do not need Danish ID for this to be relevant. Every country has its version of the CPR: the UK's National Insurance number, the US Social Security number, India's Aadhaar. And every one of those systems hands out access to banks, insurers, credit agencies and small service firms.

If you run an API that sells or shares personal data, the questions are simple. Do you cap what each customer can pull? Do you alert on usage that jumps by orders of magnitude? Would you notice before the invoice?

If you are Danish, place the credit warning, expect a wave of convincing phishing that quotes your real address back at you, and treat any unexpected call claiming to be from your bank or a public agency with suspicion. For more on how this kind of social engineering works, see our guide to vishing.

More from Future Technology