This week in identity incidents: a supplier's access exposed 8.8m Danish ID records
A supplier's access to Denmark's ID register was abused, Trump Mobile customer data was published, and ASOS, Bromcom and Nikkei show the same identity gaps.
Week ending 7 October 2026. This week's incidents share a common thread: trust placed in third parties, accounts and non-human identities that were not watched closely enough. A national ID register, a mobile carrier's supplier, a school software provider, a media group and a retailer's messaging platform all show variations on the same failure, whether that is standing access abused at scale, a partner's compromised employee, or credentials that outlived their usefulness.
The week's incidents
- Denmark's Central Population Register: The Register and an Incident Desk briefing report that an unauthorised party abused a small private company's legitimate, narrowly scoped access to the CPR, exposing names, addresses and ID numbers for around 8.8 million records. Datatilsynet describes automated lookups used to enumerate valid CPR numbers over roughly ten days before extraction, pointing to a gap between the access a system grants and the access its governance assumes is used.
- Trump Mobile: Cybernews and an Incident Desk briefing report that a group calling itself BYOD published data on 3,615 customers, including names, contact details and order information. The attackers claim the intrusion began with malware on an employee at third-party partner Liberty Mobile and that neither company was using MFA; these are claims from the threat actor and have not been independently verified.
- ASOS: An Incident Desk briefing reports that attackers sent a push notification through ASOS's own app claiming a Snowflake compromise, while ASOS confirms unauthorised activity on third-party customer-communication platforms and says basic personal data may have been accessed. This follows an earlier, separate credential-stuffing incident in August affecting 138,828 US customers, underlining that send-capable platform credentials are high-value non-human identities that are often ungoverned.
- Bromcom: The Register reports that the school software provider's legacy single sign-on registration functionality, kept running because an internal system still called it, was accessed by an unauthorised third party, exposing email addresses and limited SSO metadata for affected registrations. No passwords or authentication tokens were held in the affected component.
- Nikkei: BleepingComputer reports that attackers breached two employee email accounts, one Google Workspace and one Microsoft 365, exposing personal data on 1,646 individuals and using the second account to send 9,000 phishing emails to staff and contacts, continuing a pattern of repeated account-level compromises at the company.
- Double Counter (Discord server protection service): Have I Been Pwned reports a breach via a vulnerability in the Metabase analytics tool, exposing around 275,000 email addresses and Discord usernames, plus a smaller set of paying subscribers' names, countries and postcodes.
- DIVD (Dutch Institute for Vulnerability Disclosure): The Register reports that attackers, in what DIVD assesses was an agentic AI-driven operation, chained two Zammad zero-days to hijack sessions and escalate to root in seconds, stealing volunteer researchers' email addresses and other contact details.
Patterns this week
Four of this week's incidents trace back to third-party or supplier access that was broader, longer-lived or less monitored than intended, from Denmark's CPR register to Trump Mobile's carrier partner. Stolen or reused credentials and accounts without adequate MFA sit behind the Trump Mobile claims, Nikkei's email compromises and ASOS's earlier account takeovers, while non-human identities, legacy SSO services, messaging platform keys and service accounts, quietly outlived their intended purpose at Bromcom and ASOS alike.
One thing to do this week
Pull a list of every third-party or partner account with standing access to sensitive systems or customer data, confirm its access is scoped technically rather than just contractually, and check that lookup or usage volumes from that account are actually monitored for anomalies.
Sources and further reading
- Trump Mobile data breach exposes 3,615 users (Cybernews) (Cybernews)
- Double Counter breach added to Have I Been Pwned (274,922 accounts) (Have I Been Pwned)
- Denmark's ID register spills more people's details than the country has residents (The Register)
- Legacy sign-on service comes back to bite school software provider Bromcom (The Register)
- Nikkei discloses breaches of employees’ Microsoft, Google email accounts (BleepingComputer)
- Rejetto HFS servers now actively scanned for critical RCE flaw (BleepingComputer)
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (CISA advisories)
- AI agents hacked the hackers, stealing email addresses from security research org (The Register)
- Trump Mobile breach: 3,615 customers' data published, and what the attackers claim about how they got in (Incident Desk briefing)
- Denmark's CPR Breach: When a Lookup Number Becomes a Skeleton Key to 8.8 Million Identities (Incident Desk briefing)
- ASOS and the push notification that spoke for the attacker: secure the identities that talk to your customers (Incident Desk briefing)
Source links support the documented product behaviour. Recommendations and labelled examples are editorial guidance.