upvote
The "fun" part is that it was only caught because the bill for the lookups was higher than expected. Had the attackers done a lookup every now and then, nobody would have noticed.

Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.

The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.

reply
I'd add missing MFA as weakness number three, at minimum. Problem number 4 is that the "password" was leaked, and the company (Pays ApS) didn't figure that out. Problem number 5 - the "password" belonged to a _former_ employee. How was that account not disabled? Problem number 6 - how can a company with two employees get access to this register in the first place? Don't they need to show compliance with some security standard that would be not possible to deliver for such a small company?

If you start thinking more about this, more and more problems pop up.

reply
There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.
reply
Authentication in Denmark also uses cryptographic signatures etc.

The CPR alone is used for casual identification.

reply
Personal numbers and social security numbers in US are horrible idea, essentially a password and username simultaneously
reply
Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way.

I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.

reply
I will expand a bit further - all the data that was compromised in this breach is public by design in sweden, as far as I know. Not just the personal numbers.
reply
[flagged]
reply