The Danish government has revealed unauthorized access to the data of some 8.8 million people, including names, addresses and personal identification numbers registered in the "Central Register of Individuals," in one of the country's largest data breaches.
Hot Topics
The human body ages in leaps and bounds Scientists identify two critical ages
From your phone screen to your data How do malicious apps sneak in and steal your secrets?
It is noteworthy that the breach - according to what has been announced so far - was not through a known vulnerability in the registry itself, but rather through a legal authority that was granted to a small Danish company.
The government said in a statement Monday, reported by Bloomberg, that the activity lasted for about 10 days during September and was only detected on the evening of Friday, October 2, when a registry employee noticed unusual behavior. The following day, it became clear that it was a security incident, the full extent of which emerged over the weekend.
Digital Affairs Minister Kristina Egeland described the incident as "very serious" and ordered a thorough security review of the system, while authorities have yet to reveal who was behind the operation.
How did the delivery take 10 days?
After the incident was discovered, authorities suspended the company's access to the registry, notified the data protection authority, and the police began an investigation.
Eglund admitted to the local Ritzau news agency that the safeguards surrounding the company's access to the registry were inadequate, saying that "the security measures surrounding this company's access to the central registry were not good enough," and that "this should not have happened." She also admitted that the alarms should have been raised earlier.
The sensitivity of the matter lies in the nature of the authority that was misused. Danish law allows companies with a legitimate interest to obtain specific data about individuals who have been identified in advance, either by identity number, name and address, or name and date of birth.
If a company knows someone's number in this registry, it can use it to search for them and obtain some of their information, such as name and address. However, the registry itself does not provide private companies with the numbers of registered individuals.
Authorities have not yet revealed the name of the company whose privileges were used, nor have they explained how unauthorized individuals gained access to its account or its right to access the registry.
The large number of those affected is due to the size of the register itself. Denmark has about 6 million inhabitants, while the central register contains data on about 11 million people, including deceased people and people who have left the country.
The government said that the names and addresses of people registered with the name and address protection feature were not subject to unauthorized access.
Tags:
technology