[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbjdXTdwRwrIRapOIZOUpgEvPN77eXmG7Je_PshSvcFI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":28,"created_at":29,"published_at":30,"article":31,"tags":35,"podcasts":54},"f40bdf8d-69a3-4c12-8543-94670b17af27","third-party-access-exposes-88-million-danes-national-id-data","133cb9ff-5018-41c2-aa2f-76a58f1870a0","Third-Party Access Exposes 8.8 Million Danes' National ID Data","A private company with legitimate access to Denmark's Central Person Register (CPR) was exploited by attackers, exposing the personal identification numbers, names, and addresses of nearly the entire Danish population. The root failure lies in inadequate controls over third-party access to a highly sensitive national database — a classic supply chain trust vulnerability. The breach persisted for approximately 10 days before detection, suggesting insufficient real-time monitoring of access patterns to critical government data. This incident underscores that trusted third-party accounts represent a significant attack surface and must be subject to the same rigorous controls as internal privileged accounts.","**Immediate actions:**\n- Audit and revoke all third-party access to sensitive national or critical registers, granting only the minimum necessary permissions.\n- Implement real-time anomaly detection and alerting on all access to high-value data repositories such as population registers.\n- Require multi-factor authentication (MFA) for any external entity accessing sensitive government systems.\n\n**Long-term improvements:**\n- Establish a formal third-party access governance program with regular reviews, time-limited credentials, and contractual security obligations.\n- Apply the principle of least privilege and just-in-time (JIT) access for all vendor and partner accounts to reduce standing access windows.\n- Conduct periodic red team exercises simulating third-party account compromise against critical national infrastructure.\n\n**Detection measures:**\n- Deploy user and entity behavior analytics (UEBA) to baseline and flag unusual data access volumes or patterns from company accounts.\n- Enforce comprehensive, tamper-proof audit logging for all access to sensitive registers with log retention aligned to regulatory requirements.\n- Define and test incident response playbooks specifically for third-party account compromise scenarios, including rapid access revocation procedures.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27],"CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","CIS Control 15 – Service Provider Management","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-6 (Least Privilege)","NIST SP 800-53 AU-6 (Audit Record Review)","NIST SP 800-53 IR-6 (Incident Reporting)","NIST SP 800-53 SA-9 (External Information System Services)","GDPR Article 5(1)(f) – Integrity and Confidentiality","GDPR Article 28 – Processor Obligations","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","ISO\u002FIEC 27001:2022 A.8.3 – Information Access Restriction","ISO\u002FIEC 27001:2022 A.5.19 – Information Security in Supplier Relationships","ITIL 4 – Service Configuration Management \u002F Supplier Management Practice","published","2026-10-06T08:21:29.706653+00:00","2026-10-06T08:21:29.589+00:00",{"id":7,"url":32,"slug":33,"title":34},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fdenmark-says-attackers-accessed-cpr.html","denmark-says-attackers-accessed-cpr-data-for-8-8-million-people-via-company-acco-4a058f","Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account",[36,42,48],{"id":37,"name":38,"slug":39,"description":40,"color":41},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":43,"name":44,"slug":45,"description":46,"color":47},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":49,"name":50,"slug":51,"description":52,"color":53},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]