| ~6 MIN READ |
|
The biggest leaks this week did not need a zero-day. They needed one trusted login, one trusted brand, or one trusted employee, and attackers found all three.
PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
DATA BREACH
8.8 Million Danish ID Records Walked Out Through One Small Company's Login
Intro
Denmark has about 6 million residents. Its national ID register just leaked records on 8.8 million people.
What Happened
Attackers abused a small private company's legitimate access to the Central Population Register (CPR) in September, brute-forcing valid CPR numbers and pulling the matching names, addresses, ID numbers, dates of birth, and marital status. The count tops the population because the register's roughly 11 million records include deceased people and people who moved abroad. CPR administrators found the breach October 2; police are investigating and the company's access is blocked.
Why It's Important
The CPR number is the key to Danish healthcare, tax, and banking. Danish law lets private businesses query the register, so the weakest company with access sets the security bar for the whole country.
The Other Side
Minister Christina Egelund called it "an extremely serious incident" and briefed Parliament. Security specialist Jan Kaastrup argues the real failure is treating CPR numbers as secrets at all.
TL;DR: One small company's legitimate access let attackers brute-force Denmark's national register and walk off with 8.8 million records.
Further reading: BleepingComputer | The Register
|
|
Some teams never seem to stop moving. They're on Attio, the agentic CRM.
Every customer signal is captured in one shared context layer, always current and compounding. Agents and workflows build pipeline, chase every buying signal, and move deals forward, an always-on revenue engine running alongside your team.
With Attio, you’ll get:
Leads automatically prioritised and routed to the right rep
Expansion and risk signals caught the moment they land
Follow-ups written in your voice, already there when you arrive
Teams like Parallel, Turbopuffer, and Wordsmith build on Attio. Are you one of them?
|
|
|
Blu Dot surpasses 2,000% ROAS with self-serve CTV ads
Blu Dot used Roku Ads Manager to drive incredible results for its furniture sales event. Its strategy hinged on custom audiences and retargeting, where intent was strongest.
“Roku has been a top performer,” said Blu Dot’s Claire Folkestad. “We have seen…CPMs lower than any other CTV partner we've worked with.”
Strange but real
He Locked 3,284 Workstations for Ransom. His Search History Was Less Careful.
Intro
Most extortion crews hide behind Tor. Daniel Rhyne used his employer's admin credentials and a search engine.
What Happened
In November 2023, Rhyne, a 57-year-old engineer from Kansas City, Missouri, changed the admin password at his New Jersey industrial employer to "TheFr0zenCrew!", deleted 13 domain admin accounts, and locked staff out of 254 servers and 3,284 workstations. He then emailed coworkers "Your Network Has Been Penetrated," demanding 20 bitcoin (about $750,000). Investigators found he had searched for "how to remotely shutdown a computer usign cmd," typo included, on his laptop a week earlier. He has now been sentenced to 32 months.
Why It's Important
The scariest ransomware actor is the one who already has domain admin. No phishing, no exploit, just an insider with the keys.
The Other Side
The plot failed, nobody paid, and the evidence trail was about as subtle as the password. Most insiders are not this sloppy.
TL;DR: An engineer locked 3,000+ of his employer's machines for a $750,000 ransom, searched the how-to first, and got 32 months.
Further reading: BleepingComputer
|
Your next enterprise deal dies in security review without a SOC 2 report. Sprinto gets you audit-ready in 14 days: three sessions, AI agents collect the evidence, you approve.



