Denmark data breach exposes 8.8M people's personal data

446 points - today at 8:09 AM

Source

Comments

aiiotnoodle today at 9:29 AM
I'm seriously at a point where I'm opposed to talking to my doctor because the information may be digitally recorded and leaked, going on a flight because my passport may be used to aqquire a loan by cybercriminals, comparing car insurance because my phone will be called by robocallers selling me things or verifying my ID with websites because it might be used to associate my information with whatever else I do online.

I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.

There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.

gnull today at 9:59 AM
In Sweden, to avoid this kind of malicious leaks, we leak the residents' data officially. https://hitta.se lets you look up personal numbers, names, addresses, birthdays and sometimes phone numbers of any resident. The residents are not asked for consent, the data goes there automatically (some of my friends had success with having it removed from hitta, but it comes back once you change residence address).

It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.

What's the big deal, Danes? What do you have to hide?

(The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)

ntoskrnl_exe today at 9:24 AM
Just that easily all the private conversations of everybody in the EU can leak if Denmark succeeds at outlawing E2E encryption with its Chat Control proposal.

Not trying to downplay the situation, but I hope this will be eye opening to the responsible people.

clan today at 8:43 AM
For those not getting the scope of this. The following has been compromised for all living danish citizens and foreign nationals which have had recidence. And quite a few dead ones as well.

- Social security number

- Age

- Sex

- Family relations

- Physical address

- Protected addresses

- Sex change

This is a country with quite good health records. Unfortunately also previous problems with proper non-reversible anonymisation of said data when used for research.

Roark66 today at 11:50 AM
You know, recently a medical SaaS provider's system was hacked here in Poland as well. Medical records of 20mln people covering pre 2024 back leaked. The attackers claim to have got it via a vulnerability that any company could've had. Fine.

But inside that network the security was a joke. Basically developers used real non anonymised archival data uploaded to s3 all devs had access to, to test the software. Data containing all the private stuff mentioned.

Absolute peak of incompetence. It wouldn't be hard to anonymised the data even just by hashing the names and certain other records or replace them with dummy data.

But what annoyed me the most is there is no info about huge fine for the company. No article written by the company explaining what internal failures they will fix to prevent it happening in future.

Nothing.

Those things have to be prosecuted and punished. Otherwise no one has any incentive to keep the systems secure.

Quothling today at 9:38 AM
As someone who spend a decade in the Danish public sector, among other things working in groups on national architecture. I'd say that we reap what we sow. IT and digitalisation is not taken very serious in our public sector. In most places it's placed under something, and until recently it didn't have it's own ministry. Right now it's even a shared ministry, and there is little focus on cyber security. What has arrived in recent years is solely based on the thread of hybrid attacks from Russia.

Compare this to the ministry of transportation, which has full resources. This is despite the fact that most people in this country spend less time commuting than they do working on a computer. Not that transportation isn't important, but maybe digitalisation is as well?

My personal CPR has been leaked a couple of times though. Hilariously the first time it was leaked when a couple of unencrypted laptops were stolen from the biggest IT union in the country. We have a system in place where you can flag your CPR as having been leaked. Though I suppose now we might as well consider every one of them to be leaked. In theory a CPR on it's own was never meant to give any sort of authority or access, but again, this wasn't the practice in a lot of place. So I guess this leak may be a blessing in disguise in that sense as well, as it'll highten security because of broken trust.

bryanrasmussen today at 11:51 AM
Just to note - the population of Denmark is 6,032,304.

So essentially the whole population's data has leaked. Furthermore, the notice says mv, which is abbreviation for etc. So it says "name, address, cvr number" etc.

That etc. is funny because the Danish government has a thing called NemID which you use to log into pretty much any online service, including banking, and you can install it on your phone, and when you lose it though you can verify by calling up and giving personal information to verify it is you.

Now there are a bunch of things about this system that are contemptibly stupid and annoying that I won't go into here because of my blood pressure. But now I wonder if the mv. of the personal data covers stuff you could conceivably be using to get a new NemID.

on edit: the really young have not had their data leaked, probably, and the excess of course covers people who used to live in Denmark and left.

m12k today at 11:14 AM
This comes only a few days after a data breach was reported at the Technical University of Denmark [1], exposing the personal records of current and past students, faculty and staff. That included their CPR numbers (government id at the central person registry), that could for example be used to look up their official place of residence. All in all, it seems likely that someone just got the table they needed to join on the first breach.

[1] https://www.dtu.dk/english/newsarchive/2026/10/cyberattack-o...

madsohm today at 11:55 AM
I see this as a good thing. It means that we'll (hopefully) get stricter security revolving around using these numbers. It'll no longer be enough just to yap out a 10 digit number to "verify" you are who you say you are. We already have a (albeit heavily critiqued) national 2FA system in place (MitID).

We'll have to start treating the CPR number as just a username, instead of a password. It should never have been "secret" in the first place.

jakub_g today at 9:32 AM
In the past few months, there were several huge data leaks also:

- in Poland (from private medical companies used by doctors) with estimated 20M affected people (half of population)

- in France (from tax office), 678k people affected

With AI getting more capable, and with Russia escalating things, I unfortunately expect more to come.

archixe today at 9:13 AM
The article mentions that they accessed the information through a Danish company whose access has been revoked now. I find it really surprising that a company could access these records without any limitations on which info or how many records they can pull.
hn_submit today at 11:48 AM
I demand our representatives come up with legislation that puts hefty fines on data breaches.

Companies are opting for higher profits by not investing in securing private data entrusted to them. We need to make the balance tip the other way.

As long as there aren't any financial or criminal penalties companies will not care about data being pilfered.

deleted today at 4:26 PM
Tehnix today at 3:17 PM
They only thing I can think of that a person could get out of having my data is they can pick up my subscription at a pharmacy, where it’s normally enough to mention your CPR number, and then the pharmacy asks you to confirm what name it’s registered to.

Anything else like banking or anything official requires a MitID authentication, and no one malicious can just e.g. open a bank account in my name. They’d have to go through several authentication confirmations usually.

Are there other areas where we are lax about CPR still?

KingOfCoders today at 9:54 AM
If people don't go to jail, there will be no change.
iphonecorridor today at 12:40 PM
We probably need to value privacy less. I went to a hospital in 3rd tier city in China and all the patients were in a room milling around a doctor with their charts. He’d randomly pick a person, look at their charts, do some basic tests (looking in throat etc), and write them scripts. All with everyone listening. Seemed wild. But pretty efficient! To get my visa, I had to have a chest xray, ab ultrasound, bloodwork, ekg etc etc… it was me in line with 100 other visa folks all going from one station to the next fully hearing results or seeing everyone else. Scary! But honestly it was one of the most efficient health experiences I’ve had and I still refer to the results! (Spotted “fatty liver” and got me to drink less.)
still-learning today at 6:56 PM
Need to pay your cybersecurity people
panzi today at 5:52 PM
8.8 million people? Wikipedia says Denmark only has 6 million people! Historical data too? People from other countries that had any treatment in Denmark?
clan today at 8:19 AM
CPR is the national register of all people (Central Person Register).

CPR is the administrator. There is more information in the linked press release from the ministry:

https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...

This is a huge headline story in Denmark today and I choose to link danish content as they are the primary source.

The only current english language sources are paywalled:

https://www.thelocal.dk/20261005/hackers-get-personal-info-o...

https://www.bloomberg.com/news/articles/2026-10-05/denmark-d...

Non-paywalled but major danish news outlet (National Brodcaster):

https://www.dr.dk/nyheder/indland/live-uvedkommende-har-haft...

hastily3114 today at 9:44 AM
As someone who works with CPR data in Denmark, this does not surprise me at all. Private companies access the data through an API, and anyone who works at such a company can look up CPR data as they please.
JeanCampos today at 12:33 PM
The funny part is that the info just have any value in a system that works fairly well, but stolen data reduce the trust on the system, so decrease the value of that very thing that is being stolen...

I do not think we will ever go back to the wild west, but it is also hard to think a future that follows this very tendency.

Before we had natural disasters to worry about and now we have those + cyber ones.

cimi_ today at 10:17 AM
Denmark's population is 6 million [0], where does the diff of 2.8M come from? :)

[0] https://www.dst.dk/en/Statistik/emner/borgere/befolkning/bef...

eric4smith today at 11:13 AM
Wait... wait wait... I thought the EU "protection" laws was supposed to prevent all of this?
hoppp today at 11:20 AM
Probably everyone in Denmark got breached. That sucks but 2FA identity verification already exists to access personal info
bryanrasmussen today at 12:02 PM
deleted today at 11:56 AM
drchaim today at 10:41 AM
yeah, a this rate, we can assume all digital information will be public at some point.
ionwake today at 10:18 AM
Just so everyone understands the numbers thats basically everyone in Denmark.
sedan_baklazhan today at 6:28 PM
I’ve opened the story just to search for “Russia”

Of course, Russia is being blamed twice for this data breach in the comments.

I am not disappointed.

IceDane today at 1:35 PM
For some more context for non-danes:

Basically any company can access to an API that lets you look up CPR(~SSN) numbers, and a lot of companies have access.

What has most likely happened is such an integration has been abused - we do not yet know whether it's by mistake or by some malicious third party. It wouldn't surprise me in the slightest if this is just the result of someone's Claude agent telling them that they can improve lookup times if they just enumerate every CPR number and cache them, for example - but we don't know yet.

m00dy today at 2:15 PM
Danes have never been good at cybersecurity.
ByeByeSpace today at 5:11 PM
GDPR already says companies should only keep data they actually need. Breaches like this suggest the fines still aren't big enough to change how they behave.
rimliu today at 10:55 AM
And guess who are pushing for the Chat Control.
nephihaha today at 10:16 AM
Isn't that more than the current population of Denmark? Who were the other exposed people?
deleted today at 5:39 PM
LarsKrimi today at 9:55 AM
Altman at it again?
_s_a_m_ today at 11:51 AM
so more data breached than people live in Denmark..
rvz today at 9:34 AM
Let me guess, the Danish government will find a way to prove that GDPR doesn't apply to them.

But this is incredibly bad.

tamimio today at 3:01 PM
Lol, I remember few months ago here in HN and some swedish or danish user telling how they are happy with the amazing cashless system and society there and how it’s better than cash.. there you go, breaches happen and so it blackouts. That being said, one of the issues is private companies are allowed to request personal and private information, no matter how security is, it’s eminent to get hacked or phished, like revoult, I wanted to use their platform weeks ago and they requested to “verify my ID” refused and didn’t use it, few weeks later and they suffer a data breach because some idiot employee emailed the data to someone saying they are gov.. you can never trust, zero trust in fact. Instead, there should be a way (like tokenization) to prove the identity without the 90s method of scanning the ID like how we used to fax things back then, except it was more secure that way ironically.
amelius today at 10:47 AM
"Something is rotten in the state of Denmark"
tokai today at 12:56 PM
At least they didn't mail a CD containing data on 5 million danes directly to the Chinese this time.

It really is a nothing burger this data has been leak multiple times, and is easy for any bad actor to get their hands on at any time should they need to.

derin-picment today at 9:56 AM
[flagged]
Wittie today at 10:13 AM
[flagged]
deleted today at 9:30 AM
CurbStomper4 today at 12:58 PM
[dead]
celpgoescheeew today at 3:56 PM
[dead]
alexx-devv today at 10:18 AM
[dead]
aaron695 today at 9:33 AM
[dead]
mistermaster1 today at 11:00 AM
[dead]
goreyee today at 11:47 AM
Almost said the n-word reading that danish title...
johnwalker67 today at 8:11 AM
I am so done, my cpr is leaked oh no. Like I don't
thiagoperes today at 9:58 AM
it feels this will keep happening specifically to Europe for three reasons: a) most countries took an anti-AI approach b) they reject frontier models in favor or "Sovereign" solutions c) they're replacing software with weaker/more vulnerable options

public servant engineers are token poor and will be out of the latest defense tools