Top
Best
New

Posted by clan 14 hours ago

Denmark data breach exposes 8.8M people's personal data(www.cpr.dk)
449 points | 324 commentspage 2
archixe 13 hours ago|
The article mentions that they accessed the information through a Danish company whose access has been revoked now. I find it really surprising that a company could access these records without any limitations on which info or how many records they can pull.
haute_cuisine 11 hours ago||
Claude, calculate salaries, make no mistakes. (they probably forgot the last part)

I wonder if company used some kind of automation that decided it needs all CPRs for whatever it was doing.

hn_submit 10 hours ago||
I demand our representatives come up with legislation that puts hefty fines on data breaches.

Companies are opting for higher profits by not investing in securing private data entrusted to them. We need to make the balance tip the other way.

As long as there aren't any financial or criminal penalties companies will not care about data being pilfered.

Tehnix 7 hours ago||
They only thing I can think of that a person could get out of having my data is they can pick up my subscription at a pharmacy, where it’s normally enough to mention your CPR number, and then the pharmacy asks you to confirm what name it’s registered to.

Anything else like banking or anything official requires a MitID authentication, and no one malicious can just e.g. open a bank account in my name. They’d have to go through several authentication confirmations usually.

Are there other areas where we are lax about CPR still?

KingOfCoders 12 hours ago||
If people don't go to jail, there will be no change.
Gareth321 11 hours ago||
The EU would rather destroy our right to privacy than hold criminals accountable. If I sound bitter it's because I have become very bitter over the last decade. The EU appears very effective at picking on individuals and people who can't fight back, and absolutely toothless when it comes to taking on more powerful interests. There are very few cases of the EU tangibly improving my life over the last decade, and countless examples of making it worse.
KingOfCoders 10 hours ago||
"and absolutely toothless when it comes to taking on more powerful interests. "

Like Google and Apple?

"and countless examples of making it worse."

Which would those be? I would be interested to know.

Gareth321 10 hours ago||
> Like Google and Apple?

Yes, like Google and Apple. If you would take a look at my submission history, you'll see exactly one. It was me celebrating the passing of the Digital Markets Act more than four years ago. This Act clearly lays out requirements for gatekeepers like Apple. I summarise these requirements in a comment in the submission:

* Install any software

* Install any App Store and choose to make it default

* Use third party payment providers and choose to make them default

* Use any voice assistant and choose to make it default

* User any browser and browser engine and choose to make it default

* Use any messaging app and choose to make it default

* Make core messaging functionality interoperable. They lay out concrete examples like file transfer

* Use existing hardware and software features without competitive prejudice. E.g. NFC

* Not preference their services. This includes CTAs in settings to encourage users to subscribe to Gatekeeper services, and ranking their own services above others in selection and advertising portals

To date, Apple has implemented only a handful of these, and they have done so with malicious intent. For example, they have made the creation and distribution of third party app stores to onerous that very few companies have navigated the gauntlet and actually used it. Third party browser engines are now technically supported, but so poorly that not even Google has endeavoured to create an iOS browser engine. The worst example is app distribution. The DMA requires gatekeepers to facilitate free distribution. Apple has failed to cmoply with this for four years, and has repeatedly appealed when admonished. The Commission has been sitting on their most recent "review" for over a year now, without any updates.

The net result of all of this is that Apple has retained almost all of their duopolistic market power, and has implemented almost none of the DMA requirements. They have given us the middle finger and our legislators have gone to sleep.

> Which would those be? I would be interested to know.

I'll give you me perspective as a Danish citizen.

The EU imposed working-time recording requirements, so now I have to log my working hours every week. I'm a full time employee and I work longer and shorter weeks. Now I have to waste time each week logging my hours. My company has to waste time each week logging hours and reporting them to the government and the EU.

The EU required bottle caps to remain attached to most plastic drinks containers, so now I have to wrestle with an attached cap every time I drink from one.

The EU banned ordinary disposable plastic cutlery, plates and straws, removing products I previously had the choice to buy.

The EU introduced rules requiring consent for many non-essential cookies, helping turn everyday web browsing into an endless series of cookie banners.

The EU introduced "Strong Customer Authentication" requirements, so routine online payments and banking increasingly require additional authentication steps.

The EU abolished the €22 VAT exemption on low-value imports, making even tiny purchases from outside the EU subject to VAT. This one in particular sucks because the company or local tax authorities impose huge minimum fees, making small cross-border purchases far too expensive now.

The EU imposed expanded producer-responsibility rules on packaging, adding recycling fees, reporting requirements and compliance costs that ultimately feed into the prices I pay.

The EU passed even more extensive packaging regulations covering recyclability, recycled content, packaging minimisation and reuse, adding another layer of costs and restrictions to ordinary products.

The EU imposed increasingly strict CO2 targets on car manufacturers, financially penalising manufacturers whose fleets exceed them and increasing the pressure to make petrol and diesel cars more expensive or stop selling them.

The EU created ETS2, which from 2028 will add a carbon price to road fuels and home heating, creating another cost that fuel and energy suppliers can pass on to me.

The EU imposed sustainable aviation fuel mandates and tighter carbon rules on airlines, increasing the regulatory cost of flying.

The EU brought shipping into its carbon-pricing system and introduced FuelEU Maritime, leading shipping companies to add explicit EU environmental surcharges that feed into the cost of goods I buy.

The EU imposed Ecodesign restrictions on appliances, including maximum power limits for products such as vacuum cleaners, reducing the range of products I am allowed to buy.

The EU passed a minimum-wage directive despite Denmark already having its own collective-bargaining model, forcing Denmark to fight the EU in court to protect a labour-market system that was already working without a statutory minimum wage.

alpaca128 3 hours ago|||
> The EU abolished the €22 VAT exemption on low-value imports

Because it was abused by countless vendors that just wrote a random value below 22 Euros on the label no matter how much it cost.

> The EU introduced rules requiring consent for many non-essential cookies, helping turn everyday web browsing into an endless series of cookie banners

Not sure why you're blaming the messenger. Either way this can be solved by installing a browser plugin.

alt227 5 hours ago|||
A lot of those things you listed the EU as doing sound like good things to me.
raxxorraxor 12 hours ago|||
Problem is that the EU will even go further here and tries to implement that everyone is forced to id themselves despite the regular problems.
TacticalCoder 11 hours ago||
> If people don't go to jail, there will be no change.

The EU being the EU, it's those criticizing the leak by governments of public data that are going to be sent to jail.

KingOfCoders 10 hours ago|||
"it's those criticizing the leak by governments"

If this is a general trend in the EU, what people went to jail for criticizing the leaks?

nhma 10 hours ago|||
Oh no, the evil EU police will throw us all in EU jails!
iphonecorridor 10 hours ago||
We probably need to value privacy less. I went to a hospital in 3rd tier city in China and all the patients were in a room milling around a doctor with their charts. He’d randomly pick a person, look at their charts, do some basic tests (looking in throat etc), and write them scripts. All with everyone listening. Seemed wild. But pretty efficient! To get my visa, I had to have a chest xray, ab ultrasound, bloodwork, ekg etc etc… it was me in line with 100 other visa folks all going from one station to the next fully hearing results or seeing everyone else. Scary! But honestly it was one of the most efficient health experiences I’ve had and I still refer to the results! (Spotted “fatty liver” and got me to drink less.)
panzi 4 hours ago||
8.8 million people? Wikipedia says Denmark only has 6 million people! Historical data too? People from other countries that had any treatment in Denmark?
still-learning 3 hours ago||
Need to pay your cybersecurity people
clan 14 hours ago||
CPR is the national register of all people (Central Person Register).

CPR is the administrator. There is more information in the linked press release from the ministry:

https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...

This is a huge headline story in Denmark today and I choose to link danish content as they are the primary source.

The only current english language sources are paywalled:

https://www.thelocal.dk/20261005/hackers-get-personal-info-o...

https://www.bloomberg.com/news/articles/2026-10-05/denmark-d...

Non-paywalled but major danish news outlet (National Brodcaster):

https://www.dr.dk/nyheder/indland/live-uvedkommende-har-haft...

lode 13 hours ago||
Another non-paywalled English article from a Danish source: https://cphpost.dk/2026-10-05/life-in-denmark/cpr-data-breac...
WA 12 hours ago||
Will they be fined? (Probably not)

Will Danes be compensated for the hassle, this causes them? (Probably not)

Will Danes be hassled with GDPR-compliance in every business, school etc. even though the state can't keep records safe? (Probably yes)

zunintoku 8 hours ago||
What's with the state jab, this was a business leaking it
hastily3114 13 hours ago|
As someone who works with CPR data in Denmark, this does not surprise me at all. Private companies access the data through an API, and anyone who works at such a company can look up CPR data as they please.
spragl 10 hours ago|
That is also my impression. So I wonder how they caught this. It will be interesting if they are going to say so at some point.
More comments...