Cybersecurity · Tuesday, 6 October 2026
Attackers used a Danish company's lawful access to Denmark's population register to take the names, addresses and ID numbers of 8.8 million people
Denmark says the names, addresses and CPR numbers of 8.8 million people were taken from its national register in September, through a company allowed to search it. The register also holds people who died or moved away. Police are investigating, and nobody has been named.
8.8m
people whose names, addresses and CPR numbers were taken
The minister called it an extremely serious incident.
11m
people in the register, against just over 6m who live in Denmark
It keeps the records of people who died or moved abroad.
10 digits
in a CPR number, starting with the date of birth
A CPR number is meant to last a lifetime.
The lead story — what happened
-
Denmark says attackers took the names, addresses and CPR numbers of about 8.8 million people from its Central Person Register, the national list of everyone registered in the country.
[1] [2] -
A CPR number is a 10-digit personal number that begins with a person's date of birth. Healthcare, banks and government services all use it.
[2] -
The register holds about 11 million people, including people who have died or moved abroad. Just over six million people live in Denmark.
[2] [3] -
The attackers used the lawful access of a Danish company that is allowed to search the register, Denmark's government says. Some companies have this access to check people's details.
[3] [2] -
Denmark's Data Protection Agency says the attackers ran a very large number of automated searches to find valid CPR numbers, then pulled the record behind each one.
[2] [1] -
The searches took place in September. The register's managers found out on 2 October and worked out the size over the weekend.
[1] [3] -
Denmark's government has not named the company or said who the attackers are. Police are investigating.
[1] [5] -
Denmark's minister for digitalisation, Christina Egelund, called it an extremely serious incident and told a committee of the Danish parliament.
[1] [4] -
She has ordered a broad security review, and the national hotline for digital security is open from 8am to midnight.
[2] -
Officials warn people never to give out passwords on a call or in an email, even when the caller knows their name, address and CPR number.
[1] -
The register also records church membership and court limits on a person's legal rights, Ritzau, a Danish news agency, reports.
[4] -
The last big CPR incident was in 2015, when two unencrypted CDs holding data on more than five million people were sent by mistake to China's visa centre in Copenhagen.
[2]
Who is involved
-
Christina Egelund
Denmark's minister for digitalisation; she called the breach extremely serious and ordered a security review
-
The Central Person Register (CPR)
Denmark's national list of everyone registered, living, dead or moved away; its managers found the breach on 2 October
-
Denmark's Data Protection Agency
the country's privacy regulator; it says the attackers ran huge numbers of automated searches for valid CPR numbers
-
An unnamed Danish company
a firm allowed to search the register; the attackers used its access, and its access has been blocked
-
Danish police
investigating; nobody has been named
How it unfolded
-
2015 Two CDs with CPR data on 5 million people are sent by mistake to China's visa centre
[2] -
September Automated searches run through a Danish company's access
[1] [3] -
Fri 2 Oct The register's managers find out
[1] [3] -
Sun 4 Oct The Data Protection Agency is told
[2] -
Mon 5 Oct Denmark announces the breach and police investigate
[1] [2]
Where this points
Watch whether Denmark names the company and the attackers, and what its security review changes about which companies may search the register and how.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
Attackers used a Danish company's lawful access to pull 8.8 million records from Denmark's register.
A Belarusian activist group spent almost two years inside a Russian healthcare network.
South Korea's president says AI appears to have been used in recent break-ins at the country's banks.
A researcher says he found a way out of KVM, the Linux software that runs many cloud computers.
The US has arrested the man it says wrote Ploutus, malware that makes cash machines empty themselves.
The rest of the day
23 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
South Korea's leader says AI was used on banks
South Korea's president, Lee Jae Myung, said on Tuesday that AI programs appear to have been used in recent break-ins at the country's banks.
[7] The Financial Services Commission, the country's financial regulator, has confirmed a data breach at Shinhan Bank and attacks on others, including KB Kookmin Bank.[6] Local media report that Shinhan leaked details of 25,000 customers and Kookmin the card details of 119,000.[6] Yonhap, a Korean news agency, says Hana Bank and Woori Bank were also hit, and police have opened a full investigation.[7] Shinhan customers' details25,000Kookmin customers' card details119,000Local media figures for two of the banks. Officials have not given a full count. Why it matters — The regulator has told every financial company to check its systems that can be reached from the internet, including ones customers never use.
[6] Officials have not said which AI tools were used or who used them.[7] -
03
Exchange flaw let staff read each other's email
Microsoft released an emergency fix on 2 October for a flaw in Exchange Server, the email software many organisations run on their own computers.
[12] Anyone with a login at an organisation could use it to read other people's mailboxes and attachments there, though not mailboxes at other companies.[12] Microsoft says it has seen no attacks using the flaw, but rates an attack as more likely than usual.[12] It fixed its online version, Exchange Online, itself.[12] Why it matters — Organisations that run Exchange on their own machines have to install the fix themselves.
[12] Microsoft calls it weak authorization: the server checked that a person was logged in, but not whose mailbox they were opening.[12] -
04
Atlassian warns of a serious file flaw
Atlassian, an Australian company whose Jira and Confluence tools many teams use to plan work and share documents, told customers on Monday to update at once.
[13] A flaw rated 9.3 out of 10 lets someone with no login read certain files on the server.[13] It affects the versions companies run on their own machines, including Jira, Confluence and Bitbucket.[13] An attacker must know a file's exact name and place, and Atlassian has already fixed its cloud version.[13] Why it matters — Atlassian says some setups keep sensitive files where the flaw can reach them.
[13] It tells customers who cannot update quickly to take those servers off the internet.[13] -
05
A claimed escape from software under big clouds
A researcher, Paulos Yibelo, says he found a flaw that lets a program inside a virtual machine take over the computer running it.
[14] A virtual machine is a sealed-off pretend computer, and many of them share one real server.[14] The flaw is in KVM, part of Linux that Amazon's and Google's clouds use to run customers' machines.[14] Vercel, which paid him through its bug reward scheme, confirmed it, but no details are public yet.[14] Why it matters — Separately, 404 Media reports that Meta engineers rushed to fix several such escapes in the weeks before launching Muse, its AI assistant.
[15] A Meta source says one could have let an ordinary Muse user reach Meta's internal databases.[15] -
06
Accused maker of cash-machine malware arrested
The US Justice Department says it has arrested Anibal Alexander Canelon Aguirre, 50, who it says wrote Ploutus, malware that makes cash machines empty themselves.
[8] In March he became the first person put on the FBI's ten most wanted list for computer crime.[9] Prosecutors say his group stole more than $5.4 million in 117 attacks on US banks and credit unions between 2024 and 2025.[8] He was charged in Nebraska in December 2025 and has now appeared in court.[8] Break into the machineLoad the malwareCash pours outHow the US Treasury describes the attacks: the machine keeps paying out until it is empty or someone stops it. Why it matters — Prosecutors say the money went to Tren de Aragua, a Venezuelan gang the US calls a terrorist group, so he also faces a terrorism charge.
[8] The US Treasury put sanctions on him and seven associates last week.[8] [9] -
07
Nikkei staff account sent 9,000 scam emails
Nikkei, one of Japan's largest business media groups and the owner of the Financial Times, disclosed two break-ins at staff email accounts on Sunday.
[10] In one, an attacker took over an employee's Microsoft 365 account and on 30 September sent about 9,000 scam emails, including to journalists' sources.[10] The emails went to people who had written to Nikkei staff before, and linked to harmful websites.[10] In the other, an intruder could reach a staff Google account from late July, possibly exposing details of 1,646 people.[10] Why it matters — On Monday Daiwa Securities, Japan's second-largest share-trading firm, said hackers may have taken details of up to 110,000 customers from servers run by an outside supplier.
[10] Yamato Transport and Dai-ichi Life are among other Japanese companies to report break-ins in recent weeks.[10] -
08
Two US health firms tell 250,000 of a theft
Two US health companies are telling more than 250,000 people that their details were stolen.
[19] Clover Health, a health insurer in New Jersey, says attackers tricked three staff into giving up their accounts in July, and it reported 138,677 people affected.[19] AngMar Management Services, a Texas firm that runs offices for home-care and hospice providers, reported 126,196.[19] Its stolen files include Social Security numbers, diagnoses and prescriptions, and the Interlock ransomware gang claimed the attack in August.[19] Why it matters — Both break-ins happened in July, and the companies told the US health department in September.
[19] Clover's stolen data includes insurance and account numbers, and AngMar's includes medical histories.[19] -
09
Ukraine's biggest grocer hit by extortion
ATB, Ukraine's biggest grocery chain, confirmed a cyberattack on Monday after hackers put a ransom demand on its website.
[11] A group calling itself DataSuckers wants $400,000 and claims to hold details of 7.9 million customers, including names, phone numbers and addresses.[11] ATB says no customer data was taken and has taken some online services down.[11] The hackers then posted samples on Telegram and said they would sell the data rather than publish it.[11] Why it matters — Nobody outside has checked whether the samples are real.
[11] ATB runs more than 1,300 shops and employs over 60,000 people, and the war has already destroyed hundreds of its stores.[11] -
10
Italy fines IQVIA over patient records
Italy's data protection regulator has fined IQVIA, a large health-data company, 7 million euros, about $7.8 million.
[17] IQVIA's Italian arm built a database of about one million patients from the records of 800 family doctors.[17] It replaced names with codes, but the regulator found the codes, with birth year, illnesses, prescriptions and location, could still pick out a patient.[17] It also kept records going back to 2001, and for 3,300 patients it held names and tax numbers.[17] A code, not a nameBirth yearIllnesses and medicinesLocationEach detail on its own names nobody. The regulator found that together they could point to one patient. Why it matters — Patients were never told their records were in the database, which the regulator says broke EU privacy law.
[17] IQVIA has 120 days to change its practices and says it may appeal.[17] -
11
US Senate passes a health cyber bill
The US Senate has passed the Health Care Cybersecurity and Resilience Act, a bill from senators of both main parties, with no senator objecting.
[18] It aims to help hospitals and other health bodies stop more attacks.[18] The bill was first brought in 2024 but ran out of time, and was brought back in December 2025.[18] It now goes to the House of Representatives.[18] Why it matters — More than 730 breaches of health data hit over 270 million Americans last year, SecurityWeek reports.
[18] The 2024 attack on Change Healthcare, which handles medical bills, is believed to have exposed the data of over 190 million people.[18] -
12
Belarusian group spent two years in Russian network
Solar, a Russian security firm owned by the state telecoms company Rostelecom, says a Belarusian activist group spent almost two years inside a Russian healthcare organisation's network.
[16] It blames the Belarusian Cyber Partisans, a group formed after protests against Belarus's disputed 2020 election.[16] Solar found the intrusion in December 2025 and traced it back to early 2024.[16] The hackers reached sensitive medical data but broke nothing.[16] Why it matters — Solar says the organisation is linked to many other health bodies, and believes the hackers stayed quiet so they could use those links to reach them.
[16] Russia's Supreme Court named the group extremist in July, the first hacking group to get that label.[16] -
13
Amnesty says Morocco spied on journalists
Amnesty International has published a report saying Morocco's domestic intelligence agency, the DGST, used Pegasus spyware against activists and journalists from 2017 to 2021.
[21] Pegasus is phone-hacking software made by NSO Group, an Israeli company.[21] Amnesty says it matched 103 Moroccan phone numbers to likely targets in late 2017, 22 of them journalists or media workers.[21] The report draws on a former agency employee and was made with 14 media organisations.[21] Why it matters — Morocco has denied using Pegasus and did not answer Amnesty before the report came out.
[21] A Moroccan news site argues that a number on a target list does not prove a phone was hacked.[21] -
14
Pentagon stops using Anthropic's AI
The US Defense Department told the BBC on Monday that it has stopped using tools from Anthropic, the company that makes the Claude AI.
[24] Defense Secretary Pete Hegseth labelled Anthropic a supply-chain risk in February, after it refused to remove safety limits for military use.[24] People familiar with the matter told the BBC that Claude was still in use as late as last week, built into Maven, the US military's main data system.[24] Anthropic is suing to overturn the label.[24] Why it matters — The label is usually used for companies based in countries the US sees as a threat.
[24] The Defense Department has since signed deals with Google, xAI and OpenAI.[24] -
15
University medical school hit by ransomware
The University of Illinois Chicago says a ransomware attack, which scrambles files so a gang can demand money, shut some systems at its College of Medicine for a time.
[20] The university says the hackers stole some information from the college's servers.[20] The university says all affected systems are back, its main network was not touched and patient care at its hospital went on as normal.[20] A gang called Booba claimed the attack last week and says it took 344 gigabytes.[20] Why it matters — The university is checking whether personal, research or study records were taken and will tell anyone affected.
[20] Booba appeared in July and has claimed 49 attacks.[20] A researcher at SentinelOne, a security firm, thinks it is an older gang called Frag under a new name.[20] -
16
Texas city asks $2.3m for camera records
North Richland Hills, a suburb of Fort Worth in Texas, has told a privacy group it must hand over $2.3 million before it releases records on how its police use Flock cameras.
[22] [23] Flock sells cameras that read the number plate of every passing car.[22] The city says searching about a terabyte of messages would take 14 years of work at $15 an hour.[22] Irving asked $70,000, a Houston TV station was quoted $121,000, and the town of Sealy charged nothing.[23] North Richland Hills$2,300kHouston TV station's quote$121kIrving$70kSealy$0kWhat different Texas places asked for records on police use of Flock cameras, in thousands of dollars. Why it matters — Records like these are how misuse comes to light: an audit caught a Texas officer, Zachary Klein, searching police databases about his former girlfriend.
[23] He pleaded guilty on 30 September to 100 felony counts.[23] -
17
Dell warns of a critical update-tool flaw
Dell has told customers to fix a critical flaw in Dell System Update, a tool IT staff use to push updates onto its PowerEdge business servers.
[26] Someone with no login who can reach the server over a network could use it to run commands with full control.[26] The flaw is a path traversal, a mistake in handling file names that US agencies have urged software makers to stamp out since 2024.[26] Dell fixed four other flaws in the same tool on Thursday.[26] Why it matters — Owners have to update the tool to version 2.3.0.0 or later.
[26] The FBI and CISA, the US cyber-defence agency, say this kind of flaw has been called unforgivable since 2007.[26] -
18
FBI says several held over ShinyHunters hack
The FBI told The Register on Monday that it and its partners have arrested several people over a September hack linked to ShinyHunters, a gang that steals data and demands money.
[31] It would not discuss Saif al-Din Khader, known as Rey, who Reuters reports was detained in Jordan on 29 September and is helping the FBI.[31] The security journalist Brian Krebs has called Khader the technical operator and public face of the gang's wider group.[31] Why it matters — Kevin Beaumont, a security researcher, says Khader was among those who broke into Jaguar Land Rover in 2025.
[31] That attack stopped the carmaker's factories and left its suppliers with cancelled orders.[31] -
19
Old router flaws feed a new botnet
Two security firms, Nozomi Networks and Fortinet, describe malware called Cling or ClingSTUN that takes over home routers, video recorders and other small internet devices.
[27] [28] It joins them into a botnet, a crowd of hijacked machines that one group uses to pass on traffic and flood websites.[27] Nozomi says attempts to break in through an old flaw in Realtek router software jumped from about 5 September.[27] The malware tries about two dozen known flaws and copies itself to new devices.[28] Why it matters — Its control messages look like the normal traffic devices send to find each other on the internet.
[27] Most of the flaws it uses were fixed years ago, one in 2014, so the devices it reaches are ones nobody updated.[27] [28] -
20
Hidden programs pose as email at telecoms firms
Rapid7, a security firm, says hidden programs on mail-filtering machines at telecoms firms in South Korea and Taiwan disguise their traffic as ordinary email.
[29] One, which it calls AVERAT, talks like a mail server, so on a machine whose job is sending mail its traffic looks like normal work.[29] Others named themselves after SpamSniper, a South Korean anti-spam product, to blend in.[29] Rapid7 published the research on 2 October.[29] Why it matters — These machines sit at the edge of company networks and must accept mail from outside, so firewall rules let the attackers' trigger messages through.
[29] The programs check in about every ten minutes and can open up to ten remote command windows.[29] -
21
AI agents pass hidden orders to each other
AI agents, programs that carry out tasks on their own, now run inside millions of organisations, Ars Technica reports.
[33] Google and four other organisations have admitted flaws in how their agents hand work to each other.[33] A researcher, Syed Anas Mohiuddin, showed that instructions hidden in one agent's input get passed to a second agent, which obeys because it trusts the first.[33] Google's flaw, rated 8 out of 10, could make its database tool send requests to internal addresses.[33] Why it matters — Douglas McKee of Rapid7, a security firm, says every piece did exactly what it was built to do, which makes the attack hard to catch.
[33] Rapid7 fixed its own flaw last month, and Google now blocks unsafe addresses when its tool starts.[33] -
22
UK school software firm loses sign-in data
Bromcom, a UK company whose software many schools use for attendance, timetables and staff records, has told customers of a data breach.
[30] An outsider reached an old sign-in registration service and took email addresses and which provider, such as Microsoft or Google, people used to log in.[30] Bromcom says no passwords were held there and its main school records system was not reached.[30] The old service was still running because one of Bromcom's internal systems still used it.[30] Why it matters — Bromcom found the problem on 6 September after reports of sign-in trouble, and has now switched the old service off.
[30] It says the breach did not give access to anyone's Microsoft or Google account.[30] -
23
Debian's Linux update lists 1,313 flaws
Debian, one of the oldest free versions of Linux, published an update to its kernel, the core of the system, on 29 September.
[25] It fixes problems listed under 1,313 separate flaw numbers.[25] Linux's kernel team gives a flaw number to almost every bug fix that reaches its stable versions, so the count says little about how serious each one is.[25] The Register suspects AI bug-hunting tools explain the size of the list.[25] Why it matters — Every Debian system owner still has to install it.
[25] AI-found bug reports are already flooding the Linux security mailing list, The Register reports.[25] -
24
Pakistan finds fake government login sites
Pakistan's national cyber emergency team, NCERT, says it found fake websites using the names of key government bodies, still live on Sunday.
[32] They include a fake secure login page for Nadra, which runs the national identity database, and sites using the names of the tax board and the FIA, the federal investigation agency.[32] Such pages are built to trick people into typing in passwords and personal details.[32] NCERT says it is watching them.[32] Why it matters — NCERT told the public to check that a website is genuine before typing personal details into it.
[32] It also warned government offices about staff pasting work data into AI chat tools.[32]
Permission to look one person up is not a limit on how many
Each search by an approved Danish company passed the register's check, and a month of them reached 8.8 million people.
The twist
A permission says who may look. Unless someone also sets how many looks, or what they are for, the millionth search passes the same check as the first.
The picture
How it works
- Denmark lets some companies search its register to check people's details
- The register checks that each search comes from an approved company
- Automated searches each pass that check, one at a time
- Through September they reach 8.8 million people
- The pattern is spotted on 2 October, weeks after it began
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
The Exchange email flaw
Exchange checked that a person had a login at the organisation, then let that login open other people's mailboxes too.
-
Nikkei's scam emails
About 9,000 scam emails went out from one real staff account, because each came from a login the mail service trusted.
-
The Texas camera records
An officer allowed to search police databases used that access to look up his former girlfriend and her family, until an audit caught it.
-
Italy's fine for IQVIA
IQVIA gathered records from 800 family doctors and kept them back to 2001 without telling the patients, with no end date set for keeping them.
Where you've seen this
Bank cards
the right PIN unlocks the card, and a daily cash limit decides how much one right PIN can take
Library cards
a card lets you borrow, and a set number of books stops one card emptying the shelves
Office key cards
a badge opens the doors, and the record of which doors at what hours is what shows a badge being misused
The catch
A limit only helps if it sits above what the real job needs and below what a thief wants, and a patient thief can stay under it by searching slowly.
And the whole of it
Almost everyone in Denmark gets a CPR number at birth, and doctors, banks and government offices use it every day. None of the 8.8 million chose which companies could search for them, and none of them could see the searches.
What is really going on
Records of 8.8 million people in Denmark's national register were copied in September through a Danish company that was allowed to search it, and Denmark's government found out on 2 October.
Why it works on us — A figure as big as 8.8 million is hard to picture. The change for each person is small and close to home: a scam caller may now know their name, address and CPR number.
Who gains
-
Whoever now holds the Danish records
— Danish officials warn that a caller may know a person's name, address and CPR number, details people often take as proof a call is genuine.
[1] -
Google, xAI and OpenAI
— The US Defense Department signed deals with them while fighting Anthropic in court, and OpenAI's tools have spread in some military departments.
[24] -
Atlassian's and Microsoft's cloud services
— Both makers fixed their own cloud versions, so cloud customers had nothing to do while customers on their own servers had to update.
[13] [12] -
North Richland Hills police
— A $2.3 million price on the records keeps a privacy group from seeing how officers use Flock cameras.
[22] [23] -
DataSuckers
— By posting samples in public, the group can try to sell the data whatever ATB says about it.
[11]
Who pays
-
People in Denmark's register, including those who died or moved away
— Their CPR numbers are meant to last a lifetime and are used for healthcare, banking and government services.
[2] -
Customers of Shinhan and Kookmin banks
— Local media report that 25,000 Shinhan customers' details and 119,000 Kookmin customers' card details leaked.
[6] -
Patients of Clover Health and of AngMar's clients
— More than 250,000 people lost details that include Social Security numbers, diagnoses and prescriptions.
[19] -
People who had written to Nikkei staff
— They got scam emails from a Nikkei account they knew, and their names and email addresses may be exposed.
[10] -
Moroccan journalists and activists
— Amnesty matched 103 Moroccan phone numbers to likely spyware targets in late 2017, 22 of them journalists or media workers.
[21]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Who ran the Danish searches, and how they got the company's access.
Denmark has not named the company or the attackers, and BleepingComputer's questions about how the company was broken into went unanswered.
[1] [2] -
02
Whether the company's access is now shut.
BleepingComputer and DW report the access has been blocked or cut off, while Euronews reports Denmark's government saying it has not been revoked.
[1] [4] [5] -
03
When Denmark first saw something wrong.
The Record says the irregular activity was detected on Friday 2 October, while DW reports Denmark's digital affairs ministry was alerted to an anomaly during September.
[2] [4] -
04
Which AI tools were used on South Korea's banks, and how many customers lost data.
Officials have not said, and the 25,000 and 119,000 figures come from local media reports, not from the banks.
[7] [6] -
05
Whether ATB's customer data was really taken.
DataSuckers claims 7.9 million customer records and posted samples, ATB says nothing was taken, and nobody has checked the samples independently.
[11] -
06
What the KVM flaw is, and which clouds must fix it.
Only a screenshot and a post by Vercel's chief executive are public, with no details or fix.
[14] -
07
Whether the Belarusian group used the Russian network to reach other health bodies.
Solar says the organisation connects to many others but has not named it or said what else was reached.
[16] -
08
What was in the 344 gigabytes taken from the University of Illinois Chicago.
The university is still checking whether personal, research or study records were taken.
[20]
The US Senate passed a bill to help hospitals and other health bodies defend against cyberattacks, with no senator objecting. It now goes to the House of Representatives.
Also true today
- The man the FBI says wrote Ploutus, malware that made cash machines empty themselves, has been arrested and has appeared in a US court.
- The University of Illinois Chicago brought every system hit by ransomware back online, and patient care at its hospital went on as normal.
- A researcher who found a way out of KVM, the software under many cloud computers, reported it through Vercel's bug reward scheme, and Vercel confirmed it before any details went public.
More from Cybersecurity
Across the beats