Denmark leaks 8.8 million citizens’ ID numbers — 5ch: ‘In security, the defenders always lose’

From our other sites

The story

Someone gained unauthorized access to Denmark’s civil registration system, leaking information on roughly 8.8 million people, including their personal ID numbers. The Danish government has called it an “extremely serious situation.” In the 5ch thread reacting to the news, many commenters worried that, unlike past breaches, this one might involve AI-powered automated attacks, sparking a lively debate about the security of Japan’s own My Number system, which works on a similar principle. The thread also veered off into side chatter comparing Denmark’s population and land area to Japan’s.

Denmark: Unauthorized access to civil registry leaks 8.8 million personal ID numbers, government calls it “extremely serious” – ITmedia NEWS –

October 6, 2026, 12:41 PM

By Yuya Hayashi

Source: itmedia.co.jp / Original article here

What people said

7AnonymousOct 6, 2026 12:55
Personal data leaks have really been increasing lately.
Guess it's AI after all, huh?
20AnonymousOct 6, 2026 12:58
Re: #7
I bet there are organizations using AI to launch attacks worldwide, plus individuals just doing it for kicks.
It's been proven that with AI, you can pull off cyberattacks even without any real knowledge.
9AnonymousOct 6, 2026 12:56
Denmark lol (草 = internet slang for "lol")
My Number cards would get owned just as easily, right?
161AnonymousOct 6, 2026 13:44
Re: #9
It's probably already been hacked.
The government's just paying to keep it quiet.
11AnonymousOct 6, 2026 12:56
"A system similar to Japan's My Number"
The anti-My Number crowd is going to be thrilled about this.
14AnonymousOct 6, 2026 12:57
Could they be using AI to hack this?
That's seriously bad.
17AnonymousOct 6, 2026 12:58
Re: #14
If AI is the one finding the holes,
couldn't you just tell an AI to patch them instead?
43AnonymousOct 6, 2026 13:04
Re: #17
In the end it's just an AI cat-and-mouse game, I think.
AI is a double-edged sword for humanity.
92AnonymousOct 6, 2026 13:19
Re: #17
In security, the defenders always lose.
Same goes for crime prevention and war.

Basically it's the defending side that takes the damage,
and it's impossible to prepare a perfect countermeasure.

I think eventually even real-world crime, like burglaries,
will become something the police can't handle either.
25AnonymousOct 6, 2026 12:59
Isn't the real question more like, "so what if the info leaked"?
38AnonymousOct 6, 2026 13:01
Re: #25
The fact that this was likely done by AI, unlike past breaches, is the real problem.
It's not even on the same level as just worrying about leaked info anymore.
27AnonymousOct 6, 2026 12:59
Honestly, going back to analog is the smart move at this point.
If you're fine with digital, that's on you.
Old-fashioned cards are good enough — no need for app membership IDs.
What's scary about digital is that once you're hit, everything gets cleaned out at once.
It's convenient, but the risk is no joke.
34AnonymousOct 6, 2026 13:00
Re: #27
Even if it's a paper card,
whatever's managing it behind the scenes is still digital.
46AnonymousOct 6, 2026 13:06
AI is seriously scary, man… I miss the good old peaceful days of the internet…
54AnonymousOct 6, 2026 13:08
Re: #46
The early days of the internet were fun, man~
Everyone was young back then too.
70AnonymousOct 6, 2026 13:12
Re: #38
Why's it a problem if it's AI?
97AnonymousOct 6, 2026 13:21
Re: #70
Whoa, I think I just touched on something serious there.
It means even people with zero knowledge can carry out attacks just by giving AI instructions, and if something that directly affects the economy gets attacked, the economy could collapse.
Plus, since AI's doing the attacking, the attack frequency is insanely high, so the "one hit out of many tries" scenario becomes much easier to land.
Even a split-second vulnerability is enough to get breached now.
74AnonymousOct 6, 2026 13:13
My Number's probably already been breached too.
The government just won't admit it.
78AnonymousOct 6, 2026 13:16
Re: #74
Seems more like it was leaked/sold off on the side rather than an actual hack.
93AnonymousOct 6, 2026 13:20
Going back to standalone (offline, non-networked) systems seems like the quickest fix for data defense.
140AnonymousOct 6, 2026 13:36
Re: #93
Meanwhile, the Ministry of Defense moved all its classified info onto an American Big Tech cloud.
"Defense secrets to be run on the cloud — migration prep starts next fiscal year"
Jiji Press, August 2, 2026
https://www.jiji.com/jc/article?k=2026080100280&g=pol

Re: #92
Down at the lower levels, until just a few years ago it was one PC per several people, with only a handful of machines connected to the intranet —
most were standalone, files were swapped via USB drives, and old important documents
were kept on MO disks, except the drives for reading them don't exist anymore, so you'd have to borrow one from another department…
and by the way, if you have the physical disk but can no longer read it, that counts as a "lost document" and gets disposed of.
On top of that, security was so sloppy that until a few years ago it was fairly common for a rank-and-file employee to log into the branch manager's account and read their email.
95AnonymousOct 6, 2026 13:20
Is some kind of global cyberterrorism happening right now?
Japanese companies have also been seeing more unauthorized access lately.
Which country could be behind it, I wonder?
98AnonymousOct 6, 2026 13:21
Re: #95
Probably AI gathering intel at a level beyond normal limits.
143AnonymousOct 6, 2026 13:37
The My Number card data too, maybe…?
156AnonymousOct 6, 2026 13:41
Re: #143
Wouldn't surprise me if the My Number card system has already been breached, photo IDs and all, and the Digital Agency either can't even detect it or is just covering it up.
190AnonymousOct 6, 2026 13:54
Re: #143 Re: #156
Even if it leaks, it's not a problem.
Because the Digital Agency is exempt from liability regarding use of My Number Portal and the like.
They can't be held responsible no matter what happens — it's written right there in the terms of service.
145AnonymousOct 6, 2026 13:37
Denmark only has 6 million people?
That's a pretty small country.
183AnonymousOct 6, 2026 13:52
Re: #145
Japan's only 370,000 square kilometers?
That's a pretty small country too.
192AnonymousOct 6, 2026 13:55
Re: #183
Ranked 61st out of 197 countries worldwide.
62nd out of 235 countries and territories.

So actually it's a bit bigger than average.

Background and Key Points of This Topic

Denmark’s civil registration number (the CPR number) is, like Japan’s My Number, an identifier widely used for identity verification in government services and financial institutions. Because it’s difficult to change the number itself once it has leaked, it’s prone to secondary harm such as identity theft. The speculation that kept coming up in the thread — that AI might have been used in the attack — reflects a real concern that the technical barrier for attackers has dropped, making large-scale attacks possible even without specialized knowledge. That said, no reporting has confirmed that AI was actually behind the methods used in this particular incident, so it’s worth noting this remains speculation on 5ch’s part. Likewise, comments claiming “My Number has already leaked too” or “the government is hiding it” are unsubstantiated speculation and shouldn’t be read as fact. What’s worth taking away instead is the structural problem that large-scale personal data databases like this tend to become attack targets regardless of country, and that the defending side is almost always stuck playing catch-up.

*This article is compiled from excerpts and a summary of the 5ch (News Express+) thread “Denmark: Unauthorized access to civil registry leaks 8.8 million personal ID numbers, government calls it “extremely serious”.”

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *