Prevalent themes in the discussion
-
Scale and sensitivity of the leaked data – Commenters emphasized that the breach exposed CPR numbers, addresses, family relations, and other personal details for virtually everyone in Denmark, including foreigners and deceased individuals.
"For those not getting the scope of this. The following has been compromised for all living danish citizens and foreign nationals which have had recidence. And quite a few dead ones as well." – clan
-
Government neglect of IT security – Many pointed to a lack of priority and resources for cybersecurity in the Danish public sector, treating digitalisation as an afterthought.
"IT and digitalisation is not taken very serious in our public sector. In most places it's placed under something, and until recently it didn't have it's own ministry." – Quothling
-
Inadequacy of CPR as a secret authenticator – There was consensus that the CPR number was never suitable for authentication and should now be treated as a public identifier, with real verification handled elsewhere (e.g., MitID).
"On positive side maybe now there is no reason to use it for authentication anymore. When it was always unsuitable for that reason." – Ekaros
-
Privacy fatigue and perceived low impact of breaches – Some argued that massive data leaks have become routine and largely inconsequential for the average person, making extreme privacy measures feel futile.
"big data breaches are inconsequential for an average person." – TeMPOraL