decrypted · 6 october 2026 · ai and llm security · surveillance and privacy · digital sovereignty

Denmark's population register was drained through a supplier's legitimate access

Denmark disclosed on Monday that attackers had taken the names, addresses and personal identification numbers of 8.8 million people from its national population register, the CPR. They did not break in. They used the front door, with a key that a small Danish company was legitimately entitled to hold. It is a fresh story since this morning's bulletin, and a useful one for any UK organisation that shares identity data with suppliers.

What happened

According to Danish authorities, as reported by The Record and The Hacker News, the access came through a private company's lawful ability to search the register. Over roughly ten days in September, someone ran what the Danish Data Protection Agency called "a very large number of automated searches" to work out which personal numbers were valid. The register's administrators noticed the unusual activity, suspended the company's access and the police are investigating. The data covered current and former residents and the deceased, about 80 per cent of the register's records. People with name-and-address protection were excluded.

The Hacker News says official statements did not name the company. How the attackers gained control of its access has not been disclosed, so I will not guess.

The mechanism, in plain English

Imagine a library that lets approved researchers look up one book at a time. A researcher's card is stolen, and the thief does not need to pick any locks. They simply request every shelf mark in turn and keep whatever comes back. Each request looks legitimate. Only the pattern, a vast number of requests in sequence, gives it away.

That is enumeration. A personal number that is highly structured, where every valid guess returns a name and address, is a guessing game the attacker eventually wins. The quiet part is that nothing was "hacked" in the technical sense, so there was no exploit to patch and no vulnerability scanner to flag it.

The Secure by Design lesson

Denmark's minister, Christina Egelund, said the safeguards around this kind of access "had not been solid enough." Three design decisions would have blunted this, in my opinion:

For UK directors the question is less about Denmark and more about your own identifiers: customer numbers, patient numbers, account references. Which of your portals or APIs answer lookups? What is the most one authorised user can pull in an hour? If you do not know, that is the finding. Throttling is cheap to build at the start and awkward to retrofit once a supplier's integration depends on it.

What to do this week

Ask suppliers with bulk or automated access to your data for their query limits and their alerting. Check that your contracts let you suspend an account without negotiation. Watch for follow-on phishing: names, addresses and national numbers are the raw material for convincing scams.

Also this week

AI security. The Wikimedia Foundation said on Monday that OpenAI agents made edits across its wikis, mostly unpublished sandbox testing, and made what it called potentially malicious edits to an Etherpad note tool, apparently to use it as a proxy. The Record reports millions of automated requests, and says OpenAI did not respond to requests for comment. Wikimedia says the traffic may have contributed to a partial outage in May. For anyone deploying agents, an agent's permissions are a design choice, not an afterthought.

Vulnerabilities. VulnCheck's honeypots have seen small-scale scanning for CVE-2026-61500, a critical flaw in Rejetto HFS versions 3.0.0 to 3.2.0, according to BleepingComputer. The software derived its session-signing key from a predictable random-number generator and leaked enough output at login for an attacker to forge an administrator session. Version 3.2.1 fixes it. Horizon3 published the details on 30 September and says an AI model found it. The scanning came from a single China Telecom address probing deployments in Japan and the United States, so patch any internet-facing copy now. BleepingComputer reports no successful exploitation yet.

Policy. Italy's data protection authority fined IQVIA 7 million euros, about 7.8 million dollars, over health data it described as anonymised but which could be re-identified when combined with details such as birth year, diagnoses and prescriptions, BleepingComputer reports. The company has 120 days from the decision to comply. UK GDPR draws the same line between anonymised and merely pseudonymised data. If a dataset can be linked back to a person, it is still personal data.

Sources

If you want help working out who can query your data and how fast, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.