← Back to Daily Briefing (Systematic A/S)

Systematic A/S CPR Access Application IDOR Vulnerability Leads to Danish CPR Register Breach

Published October 6, 2026

In early October 2026, threat actors exploited an Insecure Direct Object Reference (IDOR) in Systematic A/S’s CPR access REST API (endpoint /api/v1/cpr/{id}) that lacked role‑based authorization checks. Using a compromised service‑account token obtained via phishing, they enumerated sequential identifiers to exfiltrate approximately 8.8 million CPR records—names, dates of birth, addresses, gender, and CPR numbers—covering virtually the entire Danish population. The breach was detected by a SIEM spike in GET requests, leading to immediate API shutdown, a forensic investigation by Datatilsynet and CERT‑DK, and a Systematic A/S patch (v2.3.1) within 48 hours that added mandatory authorization middleware and enhanced audit logging.

  • Incident Overview
  • Discovered early Oct 2026 via anomalous SIEM log activity.
  • Exposed ~8.8 M CPR records (≈100% of Danish residents).
  • Immediate API endpoint shutdown and public notification via e‑Borger.dk.

  • Attack Vector & Vulnerability Mechanics

  • IDOR flaw: missing validation of authenticated user role against requested CPR ID.
  • Attackers used a phishing‑compromised municipal service‑account token.
  • Automated script performed sequential ID enumeration over a 12‑hour window.

  • Impact & Exploitation Status

  • Data exposed: full name, CPR number, DOB, address, gender, limited marital status.
  • Potential misuse: identity theft, fraudulent loans, targeted phishing, synthetic IDs.
  • Regulatory risk: possible GDPR fines up to 4% of global turnover; remediation >DKK 200 M.

  • Detection, Mitigation & Remediation

  • SIEM detected spike in GET /api/v1/cpr/* with odd user‑agents; firewall logged exfiltration to external ASN.
  • Implemented RBAC checks, tightened token scopes, deployed WAF rules against ID‑enumeration.
  • Patch v2.3.1 released within 48 h; nationwide credit‑freeze offers and MFA acceleration for government services.

  • Conclusion & Lessons Learned

  • Enforces strict role‑based access and token scoping for all government‑facing APIs.
  • Highlights necessity of rigorous third‑party software security assessments and continuous monitoring.
  • Rapid patching and clear communication reduced further exposure but underscores systemic supply‑chain risk.

Related posts

  1. The Hacker News — Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
  2. The Record by Recorded Future — Data breach at Denmark’s national population register exposes 8.8 million people
  3. SC Media — Hackers accessed names, addresses, and CPR numbers of 8.8 million people in Denmark
  4. Insurancejournal
  5. Straitstimes
  6. Dealroom
  7. Cybersecurity-insiders
  8. Rodtrent
  9. Aa
  10. Pmc
  11. Irishtimes
  12. Qz
  13. Cybersecuritynews

LINK COPIED TO CLIPBOARD