Privacy
Denmark's CPR Register Breach Hits 8.8 Million; FBI Cuts Accenture After PeopleSoft Hack
Denmark's national register exposed 8.8 million records, the FBI removed an Accenture contractor over an unpatched system, and Indonesia passed a sweeping data law.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Denmark’s Central Person Register Breach Exposes Data of 8.8 Million People
Denmark’s Central Person Register (CPR) is notifying roughly 8.8 million people that their personal information was stolen after hackers used a Danish company’s lawful access to exfiltrate data. The register, established in 1968, holds information on about 11 million people, including residents, emigrants, and the deceased. The breach was discovered Friday after abnormal system behavior was reported in September; names, addresses, and CPR numbers of approximately 8.8 million registered individuals were accessed. People who chose name and address protection are unaffected. CPR terminated the private company’s access, notified the Danish Data Protection Agency, and launched a police investigation. It could not name the threat actor and said it would review security policies.
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register - SecurityWeek →
FBI Removes Accenture Contractor After Unpatched System Led to Breach
The FBI removed an Accenture contractor from its work after a breach exposed personal data of thousands of bureau staff. A senior FBI official said the unnamed contractor had failed to apply a security patch to a system in its care; the FBI acted Monday and moved to mitigate risk. Sources identified the platform as Oracle PeopleSoft, an HR system, with Accenture responsible for it. ShinyHunters said last month it used a PeopleSoft flaw to break into the FBI’s jobs portal and claimed to hold data on almost all FBI agents and applicants. The group called the attack revenge over a May advisory, not a ransom bid. Two members have since been arrested.
Accenture contractor removed from FBI after unpatched system led to breach →
Rand Paul Blocks Kids Online Safety Act as Senate Clock Runs Down
Senator Rand Paul (R-KY) blocked a unanimous consent request on September 30 to pass the Kids Online Safety Act without a recorded vote, forcing supporters onto a slower path with fewer than twelve weeks before the 119th Congress expires. The bill, S. 1748, co-authored by Sens. Blumenthal and Blackburn, would impose a duty of care on social media platforms to prevent harms to minors, including eating disorders, self-harm, and compulsive-use features. Paul argues the knowledge standard would require age verification at scale and stifle protected speech. The block did not defeat KOSA or its 76 co-sponsors. The House passed a rival KIDS Act in June.
Rand Paul Blocks Kids Online Safety Act: Senate Has Weeks to Pass Duty-of-Care Bill →
Indonesia Passes One Data Indonesia Law Covering AI and Blockchain
Indonesia’s House of Representatives passed the One Data Indonesia bill into law in Jakarta on October 6, 2026, after all parliamentary factions backed it in a plenary session. The law sets rules for national data governance, including AI and blockchain use, and places National Basic Data under state control as the main reference for development planning, fiscal policy, budgeting, and social aid distribution. It provides for a One Data Indonesia institution reporting to the president and sets standards for metadata, reference codes, national data catalogs, and interoperability. Access to closed data and transfers outside Indonesia’s jurisdiction require parliamentary approval, and data operators must report incidents within 24 hours. The law includes administrative sanctions and criminal provisions.
Indonesia’s House passes data law covering AI, blockchain →