Denmark Data Breach Exposes 8.8M People's Personal Data
Points and comments are a snapshot, not live.
A Danish company's misused access exposed 8.8 million CPR records.
Denmark's Central Person Register (CPR) suffered a data breach after an unauthorized actor misused a Danish company's legitimate access to the CPR system. The breach exposed names, addresses, and CPR numbers of approximately 8.8 million registered individuals. CPR administration revoked the company's access, reported the incident to the Danish Data Protection Agency, and police are investigating. Personal data of individuals with name and address protection was not compromised.
What commenters are saying
Commenters widely express frustration and concern that Denmark's CPR number is often used for authentication, despite its unsuitability. Many note this leak, combined with the power of social engineering, will enable large-scale scams. Several point out other deeply concerning implications: exposed family relations, sex changes, and the ability to identify individuals with protected addresses. The thread splits into two camps: those arguing this will force better security practices, and those predicting no meaningful change (no fines, no compensation, continued GDPR hassles for citizens but not the state).