Third-Party Access Exposes 8.8 Million Danes' National ID Data
A private company with legitimate access to Denmark's Central Person Register (CPR) was exploited by attackers, exposing the personal identification numbers, names, and addresses of nearly the entire Danish population. The root failure lies in inadequate controls over third-party access to a highly sensitive national database — a classic supply chain trust vulnerability. The breach persisted for approximately 10 days before detection, suggesting insufficient real-time monitoring of access patterns to critical government data. This incident underscores that trusted third-party accounts represent a significant attack surface and must be subject to the same rigorous controls as internal privileged accounts.
Tactical Insight
Immediate actions
- Audit and revoke all third-party access to sensitive national or critical registers, granting only the minimum necessary permissions.
- Implement real-time anomaly detection and alerting on all access to high-value data repositories such as population registers.
- Require multi-factor authentication (MFA) for any external entity accessing sensitive government systems.
Long-term improvements
- Establish a formal third-party access governance program with regular reviews, time-limited credentials, and contractual security obligations.
- Apply the principle of least privilege and just-in-time (JIT) access for all vendor and partner accounts to reduce standing access windows.
- Conduct periodic red team exercises simulating third-party account compromise against critical national infrastructure.
Detection measures
- Deploy user and entity behavior analytics (UEBA) to baseline and flag unusual data access volumes or patterns from company accounts.
- Enforce comprehensive, tamper-proof audit logging for all access to sensitive registers with log retention aligned to regulatory requirements.
- Define and test incident response playbooks specifically for third-party account compromise scenarios, including rapid access revocation procedures.