The Hacker News • 4h
Systematic A/S CPR Access Application IDOR Vulnerability Leads to Danish CPR Register Breach
In early October 2026, threat actors exploited an Insecure Direct Object Reference (IDOR) in Systematic A/S’s CPR access REST API (endpoint /api/v1/cpr/{id}) that lacked role‑based authorization checks. Using a compromised service‑account token obtained via phishing, they enumerated sequential identifiers to exfiltrate approximately 8.8 million CPR records—names, dates of birth, addresses, gender, and CPR numbers—covering virtually the entire Danish population. The breach was detected by a SIEM spike in GET requests, leading to immediate API shutdown, a forensic investigation by Datatilsynet and CERT‑DK, and a Systematic A/S patch (v2.3.1) within 48 hours that added mandatory authorization middleware and enhanced audit logging.