Europe
Denmark CPR
Denmark's Central Person Register (CPR) is notifying approximately 8.8 million people that their personal information was stolen in a data breach.
CPR is Denmark's national civil registration system, containing information on around 11 million people, including residents, emigrants and deceased individuals. On October 5, CPR announced that hackers exploited a Danish company's lawful access to the system to exfiltrate personal information. Under Danish law, private companies with a legitimate interest are granted access to the CPR to obtain information on specific individuals.
The organization confirmed that the attackers accessed the names, addresses and CPR numbers, the equivalent of Social Security numbers, of approximately 8.8 million registered individuals, both living and deceased.
How it could affect your business
The exposed information gives attackers everything they need to commit long-term identity fraud, opening fraudulent accounts, taking out loans or impersonating individuals in ways that can take years to unravel. Businesses should remind customers and employees to monitor their credit reports and financial accounts closely for unusual activity and to act quickly by placing a fraud alert or credit freeze if they suspect their information has been misused.
