From our other sites
The story
Someone gained unauthorized access to Denmark’s civil registration system, leaking information on roughly 8.8 million people, including their personal ID numbers. The Danish government has called it an “extremely serious situation.” In the 5ch thread reacting to the news, many commenters worried that, unlike past breaches, this one might involve AI-powered automated attacks, sparking a lively debate about the security of Japan’s own My Number system, which works on a similar principle. The thread also veered off into side chatter comparing Denmark’s population and land area to Japan’s.
Denmark: Unauthorized access to civil registry leaks 8.8 million personal ID numbers, government calls it “extremely serious” – ITmedia NEWS –
October 6, 2026, 12:41 PM
By Yuya Hayashi
Source: itmedia.co.jp / Original article here
What people said
Guess it's AI after all, huh?
I bet there are organizations using AI to launch attacks worldwide, plus individuals just doing it for kicks.
It's been proven that with AI, you can pull off cyberattacks even without any real knowledge.
My Number cards would get owned just as easily, right?
It's probably already been hacked.
The government's just paying to keep it quiet.
The anti-My Number crowd is going to be thrilled about this.
That's seriously bad.
If AI is the one finding the holes,
couldn't you just tell an AI to patch them instead?
In the end it's just an AI cat-and-mouse game, I think.
AI is a double-edged sword for humanity.
In security, the defenders always lose.
Same goes for crime prevention and war.
Basically it's the defending side that takes the damage,
and it's impossible to prepare a perfect countermeasure.
I think eventually even real-world crime, like burglaries,
will become something the police can't handle either.
The fact that this was likely done by AI, unlike past breaches, is the real problem.
It's not even on the same level as just worrying about leaked info anymore.
If you're fine with digital, that's on you.
Old-fashioned cards are good enough — no need for app membership IDs.
What's scary about digital is that once you're hit, everything gets cleaned out at once.
It's convenient, but the risk is no joke.
Even if it's a paper card,
whatever's managing it behind the scenes is still digital.
The early days of the internet were fun, man~
Everyone was young back then too.
Why's it a problem if it's AI?
Whoa, I think I just touched on something serious there.
It means even people with zero knowledge can carry out attacks just by giving AI instructions, and if something that directly affects the economy gets attacked, the economy could collapse.
Plus, since AI's doing the attacking, the attack frequency is insanely high, so the "one hit out of many tries" scenario becomes much easier to land.
Even a split-second vulnerability is enough to get breached now.
The government just won't admit it.
Seems more like it was leaked/sold off on the side rather than an actual hack.
Meanwhile, the Ministry of Defense moved all its classified info onto an American Big Tech cloud.
"Defense secrets to be run on the cloud — migration prep starts next fiscal year"
Jiji Press, August 2, 2026
https://www.jiji.com/jc/article?k=2026080100280&g=pol
Re: #92
Down at the lower levels, until just a few years ago it was one PC per several people, with only a handful of machines connected to the intranet —
most were standalone, files were swapped via USB drives, and old important documents
were kept on MO disks, except the drives for reading them don't exist anymore, so you'd have to borrow one from another department…
and by the way, if you have the physical disk but can no longer read it, that counts as a "lost document" and gets disposed of.
On top of that, security was so sloppy that until a few years ago it was fairly common for a rank-and-file employee to log into the branch manager's account and read their email.
Japanese companies have also been seeing more unauthorized access lately.
Which country could be behind it, I wonder?
Probably AI gathering intel at a level beyond normal limits.
Wouldn't surprise me if the My Number card system has already been breached, photo IDs and all, and the Digital Agency either can't even detect it or is just covering it up.
Even if it leaks, it's not a problem.
Because the Digital Agency is exempt from liability regarding use of My Number Portal and the like.
They can't be held responsible no matter what happens — it's written right there in the terms of service.
That's a pretty small country.
Ranked 61st out of 197 countries worldwide.
62nd out of 235 countries and territories.
So actually it's a bit bigger than average.
Background and Key Points of This Topic
Denmark’s civil registration number (the CPR number) is, like Japan’s My Number, an identifier widely used for identity verification in government services and financial institutions. Because it’s difficult to change the number itself once it has leaked, it’s prone to secondary harm such as identity theft. The speculation that kept coming up in the thread — that AI might have been used in the attack — reflects a real concern that the technical barrier for attackers has dropped, making large-scale attacks possible even without specialized knowledge. That said, no reporting has confirmed that AI was actually behind the methods used in this particular incident, so it’s worth noting this remains speculation on 5ch’s part. Likewise, comments claiming “My Number has already leaked too” or “the government is hiding it” are unsubstantiated speculation and shouldn’t be read as fact. What’s worth taking away instead is the structural problem that large-scale personal data databases like this tend to become attack targets regardless of country, and that the defending side is almost always stuck playing catch-up.
*This article is compiled from excerpts and a summary of the 5ch (News Express+) thread “Denmark: Unauthorized access to civil registry leaks 8.8 million personal ID numbers, government calls it “extremely serious”.”

Leave a Reply