Faultline Faultline Kommando 161

Germany · taz · · 4h

Massive data theft: hacker attack on the central population register in Denmark

Deutsch (original) · Auto-translated to English

It involves almost nine million names, addresses and personal identity numbers: Denmark reports the largest data attack to date on its central CPR register of people. Digitalization Minister Christina Egelund called it a “deeply serious incident” on Monday. According to her ministry, unknown persons initially used legal access to the system in order to then access the huge amounts of data in an as yet unknown way.

It is not yet possible to say who is behind it. The ministry said in a statement that they were in the process of getting an overview of what was happening together with all relevant authorities. The Danish broadcaster DR reported that the NSA had taken over the investigation - a national police unit responsible, among other things, for cybercrime.

The CPR administration noticed on Friday that there had been irregularities in the system during September. It is now clear that unauthorized persons used the legal access of a Danish company to get the data. The conditions under which companies can search for data in the register are regulated by law. In addition to a legitimate interest, they must already have some of the information; the group of people is also limited, as the Ministry of Digitalization emphasized.

The rule for data searches in the CPR is that you can only get the information that you absolutely need, as Jens Myrup Pedersen described it in the DR. The professor of cybersecurity at Aarhus University rated what happened as the largest data security breach in the CPR to date. Mainly because both the identity numbers and the associated addresses are affected.

According to Minister Egelund, changes have already been made to prevent similar abuse of access in the future. She also asked for a thorough security check of the entire system. The so-called CPR number is a central part of everyday social life in Denmark. It is used for identification in all contacts with authorities and in the health system, for example. In the worst case scenario, the data could be misused for identity theft and phishing, the minister said.

The population is now asked to be particularly careful when handling their data. Under no circumstances should you give out passwords, even if the request comes from a reputable source by telephone or email.

In Denmark, the enormous amount of data sets affected also caused confusion, as it significantly exceeds the number of six million inhabitants. This is because it also includes data from people who have already died and from Danes abroad, the ministry said. A total of around eleven million people are registered in the register, which was started in 1968.

Read the full story at the source

Source: taz