So it was actually two weaknesses:
* The non-password at a two-person IT company (Pays ApS)
* And then completely unchecked access to the CPR database for 22 days which apparently does not have monitoring or limits if someone tries to access all the records (they must have made some 16k downloads per hour).
The "fun" part is that it was only caught because the bill for the lookups was higher than expected. Had the attackers done a lookup every now and then, nobody would have noticed.
Apparently no one cares, until it becomes a financial issue. IT professionels have pointed out that the system is deeply flawed for 15 - 20 years, at least, but every issue has been papered over with more IT, tweaks to software and websites. The fundamental issues have never been addressed.
The average Dane doesn't even care. They'll just complain that they need to scan their health card, rather than shouting their CPR number across the pharmacy. Thousands of people have access to the system every day, abuse happens daily, but no one seems to care, because there hasn't been an actual costs associated with that abuse.
I'd add missing MFA as weakness number three, at minimum. Problem number 4 is that the "password" was leaked, and the company (Pays ApS) didn't figure that out. Problem number 5 - the "password" belonged to a _former_ employee. How was that account not disabled? Problem number 6 - how can a company with two employees get access to this register in the first place? Don't they need to show compliance with some security standard that would be not possible to deliver for such a small company?
If you start thinking more about this, more and more problems pop up.
There's also the weakness that the security relies ok this information being secret. Denmark make use the personal numbers for a form of authentication, but the numbers are readable to many people. In sweden, this data is public by design. Authentication happens using public/private key and other secure mechanisms.
Authentication in Denmark also uses cryptographic signatures etc.
The CPR alone is used for casual identification.
Personal numbers and social security numbers in US are horrible idea, essentially a password and username simultaneously
Just to expand slightly on this: Some old procedures, probably from the main frame age, live to this day in old institution, including the belief that you can ask people about their personal number over the telephone and auth them that way.
I don't think any IT infrastructure is doing it, it's all by a national single-sign on system.
I will expand a bit further - all the data that was compromised in this breach is public by design in sweden, as far as I know. Not just the personal numbers.
[flagged]