105 points clan 2 hours ago 60 comments
johnwalker67 2 hours ago | parent
clan 1 hour ago | parent
Ekaros 1 hour ago | parent
clan 49 minutes ago | parent
But since then I have experienced how scared mugglers get when they get a threatning mail with the only legitimacy of naming and old leaked password.
This will be easy to exploit on a scale.
Scammers used to prey on the weakest hence the many Nigerian Princes. But as they get more sophisticated and move up the chain they start to look more and more legitimate.
aDyslecticCrow 1 hour ago | parent
clan 2 hours ago | parent
CPR is the administrator. There is more information in the linked press release from the ministry:
https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
This is a huge headline story in Denmark today and I choose to link danish content as they are the primary source.
The only current english language sources are paywalled:
https://www.thelocal.dk/20261005/hackers-get-personal-info-o...
https://www.bloomberg.com/news/articles/2026-10-05/denmark-d...
Non-paywalled but major danish news outlet (National Brodcaster):
https://www.dr.dk/nyheder/indland/live-uvedkommende-har-haft...
lode 1 hour ago | parent
clan 1 hour ago | parent
- Social security number
- Age
- Sex
- Family relations
- Physical address
- Protected addresses
- Sex change
This is a country with quite good health records. Unfortunately also previous problems with proper non-reversible anonymisation of said data when used for research.
delamon 44 minutes ago | parent
toyg 22 minutes ago | parent
LarsKrimi 10 minutes ago | parent
I did it accidentally during my last move and it was a pain in the behind
And it expires after a year by default so it feels rather pointless
Mashimo 6 minutes ago | parent
I managed to get protected address, it's just to log in somewhere and request it. I can't remember the details, but it made for example banking _slightly_ more annoying. They would call me so they can send me a letter. Also makes it harder for people who know your name to look up your address.
Never managed to get my name removed from my domain whois and at some point removed protected address again. In theory, if I share one of my other .com domains on the internet, an attacker could reverse DNS the IP, find my DK domain and thus get my full name and address.
kasperni 36 minutes ago | parent
wodenokoto 31 minutes ago | parent
There are exceptions where the encoded birth date will be wrong (like immigrants with unknown birth dates) or dates where there are more people than the 4 digits that encode checksum validation and gender can handle.
vasusai 28 minutes ago | parent
Additionally it was via third party access granted to private companies.
https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfatt...
Mashimo 22 minutes ago | parent
archixe 1 hour ago | parent
ntoskrnl_exe 55 minutes ago | parent
Not trying to downplay the situation, but I hope this will be eye opening to the responsible people.
raxxorraxor 9 minutes ago | parent
aiiotnoodle 50 minutes ago | parent
I don't think, for a vast majority of cases, these companies I'm forced to interact with can be trusted with my data and it's having a real world negative impact. Even with the best intentions the information is somehow valuable to steal and I'm baffled how it's not secure.
There should be some consequences for companies asking for things like SSN/National Insurance numbers on job adverts or retaining drivers licence photos after test driving a car, they just don't need the data anymore.
amelius 45 minutes ago | parent
Razengan 40 minutes ago | parent
Why can’t WE spy on them 24/7?
lynx97 33 minutes ago | parent
I am writing this because I don't think democracy works as advertised.
sparkling 23 minutes ago | parent
ElDji 34 minutes ago | parent
toyg 26 minutes ago | parent
But nobody really cares enough to spend money modernising this sort of system.
carlosjobim 16 minutes ago | parent
peri-cl 15 minutes ago | parent
Maybe HN's still on the pro-privacy side on the car-tracking cameras stuff, but, with regards to where people sleep at night, that frog has been thoroughly boiled.
GJim 11 minutes ago | parent
Are you 'avin a laugh mate?
A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.
The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.
toyg 7 minutes ago | parent
If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you.
rithdmc 8 minutes ago | parent
I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere.
toyg 4 minutes ago | parent
Scaled 6 minutes ago | parent
tokioyoyo 34 minutes ago | parent
I’ve switched to operate with the idea that my information has already been leaked at some point. I should be generally ready to fix the problems if/when identity theft happens, rather than inconveniencing myself and figuring out the third party trust situation.
strideashort 26 minutes ago | parent
Sending my file over to lawyers in a semi-safe way has proved impossible.
And in any case, i received an answer with lots of PI over a plain email…
Absolutely maddening
ratg13 21 minutes ago | parent
In this case, the EU does have consequences for data breaches where proper protocols are not followed.
Additionally, this is not private information .. most anyone can look this information up. ID numbers are not confidential information like SSNs are treated in the US.. they are just a number to tell person A from person B. You give this number to everyone without thinking about it because it's how every company you interact with identifies you.
In this case a rogue company, or compromised company, used their access to contact the central database to download everyone's information.
In my country we essentially use the same system, except for we still allow companies to download the whole database if they want to instead of making individual queries.
In this case the access to their system was unauthorized, and under GDPR data breaches have to be reported within 72 hours. Companies can't make the decision on their own that it's not a big deal.
suslik 12 minutes ago | parent
All my data is out there, one way or another, and a dedicated cybercriminal - or worse, a government entity - can obtain or exfiltrate it without issues. I know it, they know it, everyone knows it.
The only thing I can change now is my reaction to this fact, and although the idea of off grid autarky is tempting, I am not there yet. I just don't want to stop living - flying abroad, going to doctors - I just accept that privacy in the current state of human condition is impossible, and move on with my life.
mdp2021 4 minutes ago | parent
Let me say "Hi mate, +1". State doctors? There are territories in which a pharmacological prescription is shared DB only now (where previously they could be on paper - a secret between you, the pen, the paper, the pharmacist and the gods. Private entities? Good luck finding one that does not require a privacy waiver as a condition for the visit. Searching for a medical dock, calling them to ask? "This is a recorded message. If you proceed with the call then you agree..." (Hang-up click.)
jakub_g 47 minutes ago | parent
- in Poland (from private medical companies used by doctors) with estimated 20M affected people (half of population)
- in France (from tax office), 678k people affected
With AI getting more capable, and with Russia escalating things, I unfortunately expect more to come.
233mhz 25 minutes ago | parent
Quothling 41 minutes ago | parent
Compare this to the ministry of transportation, which has full resources. This is despite the fact that most people in this country spend less time commuting than they do working on a computer. Not that transportation isn't important, but maybe digitalisation is as well?
My personal CPR has been leaked a couple of times though. Hilariously the first time it was leaked when a couple of unencrypted laptops were stolen from the biggest IT union in the country. We have a system in place where you can flag your CPR as having been leaked. Though I suppose now we might as well consider every one of them to be leaked. In theory a CPR on it's own was never meant to give any sort of authority or access, but again, this wasn't the practice in a lot of place. So I guess this leak may be a blessing in disguise in that sense as well, as it'll highten security because of broken trust.
Mashimo 18 minutes ago | parent
I think I get what you are trying to say, but just for other people reading this: Denmark is one of the "best" / advanced countries when it comes to IT and digitalisation in public sector in Europe.
hastily3114 35 minutes ago | parent
LarsKrimi 24 minutes ago | parent
thiagoperes 22 minutes ago | parent
public servant engineers are token poor and will be out of the latest defense tools
Mashimo 17 minutes ago | parent
gnull 20 minutes ago | parent
It's quite convenient, when you meet a new friend, to go and check what neighbourhood they're from, who do they live with and where they lived before.
What's the big deal, Danes? What do you have to hide?
(The provocative tone is intentional as a joke, I'm not even a Swede, I just find the brotherly rivalry between Scandinavians amusing.)
sajithdilshan 17 minutes ago | parent
Boltgolt 8 minutes ago | parent
Gravityloss 7 minutes ago | parent
aranelsurion 3 minutes ago | parent
Not that any other country does much better in this regard. Still it sounds a little wild to me that you can get this information without even needing to hit a shady forum and download some csv. Maybe lowers the bar too much.
nephihaha 3 minutes ago | parent