The exfiltration of 8.8M Danish CPR records exposes the systemic risk of partner API queries. Security leaders must replace static trust with verifiable credentials.
Danish authorities confirmed an unauthorized entity abused legitimate commercial partner API credentials to exfiltrate 8.8 million CPR citizen identity records.