Denmark CPR Data Breach Exposes 8.8 Million Records via Company Account Access
Unauthorized actors exploited lawful access rights to extract names, addresses, and personal identification numbers from the national population register

Key Takeaways
- Unauthorized access to Denmark's CPR register exposed data for 8.8 million individuals, including deceased persons.
- The breach was facilitated through a private company's lawful access rights to the register.
- Exposed data includes names, addresses, and personal identification numbers (CPR numbers).
Related Security News

ASOS Confirms Data Breach Following Unauthorized In-App Notifications
ASOS has confirmed a data breach after unauthorized push notifications were sent through its mobile app. The threat actors claim to have stolen customer data from the company's Snowflake environment, though details regarding the scale and specific data elements remain unverified.

IQVIA Fined €7 Million by Italian Data Protection Authority Over Health Data Anonymization Failings
Italy's Data Protection Authority (GPDP) has imposed a €7 million ($7.8 million) fine on IQVIA for poor data-processing practices. The authority states that the company's handling of health data could have put approximately one million patients at risk of exposure and de-anonymization. The ruling highlights failures in anonymization procedures rather than a confirmed data breach or cyber attack.



