Decrypted: The UK Cyber Briefing
Oct 6, 2026 · 4 min · 4 segments
Attackers took names, addresses and personal numbers for 8.8 million people from Denmark's national register using a company's lawful access. The design lesson on throttling and monitoring applies to…
Next, what happened? According to Danish authorities, as reported by The Record and The Hacker News, the access came through a private company's lawful ability to search the register.
Over roughly ten days in September, someone ran what the Danish Data Protection Agency called a very large number of automated searches to work out which personal numbers were valid.
The register's administrators noticed the unusual activity and suspended the company's access.
The police are investigating.
The data covered current and former residents and the deceased.
That's about eighty percent of the register's records.
People with name and address protection were excluded.
The Hacker News says official statements didn't name the company.
How the attackers gained control of its access hasn't been disclosed, so I won't guess.
Imagine a library that lets approved researchers look up one book at a time.
A researcher's card is stolen.
The thief doesn't need to pick any locks.
They simply request every shelf mark in turn and keep whatever comes back.
Each request looks legitimate.
Only the pattern, a vast number of requests in sequence, gives it away.
That's enumeration.
A personal number that's highly structured, where every valid guess returns a name and address, is a guessing game the attacker eventually wins.
The quiet part is that nothing was hacked in the technical sense, so there was no exploit to patch and no vulnerability scanner to flag it.
Next, what happened? According to Danish authorities, as reported by The Record and The Hacker News, the access came through a private company's lawful ability to search the register.
Over roughly ten days in September, someone ran what the Danish Data Protection Agency called a very large number of automated searches to work out which personal numbers were valid.
The register's administrators noticed the unusual activity and suspended the company's access.
The police are investigating.
The data covered current and former residents and the deceased.
That's about eighty percent of the register's records.
People with name and address protection were excluded.
The Hacker News says official statements didn't name the company.
How the attackers gained control of its access hasn't been disclosed, so I won't guess.
Imagine a library that lets approved researchers look up one book at a time.
A researcher's card is stolen.
The thief doesn't need to pick any locks.
They simply request every shelf mark in turn and keep whatever comes back.
Each request looks legitimate.
Only the pattern, a vast number of requests in sequence, gives it away.
That's enumeration.
A personal number that's highly structured, where every valid guess returns a name and address, is a guessing game the attacker eventually wins.
The quiet part is that nothing was hacked in the technical sense, so there was no exploit to patch and no vulnerability scanner to flag it.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.