Skip to content
Back to incidents
Hacking1 April 2012

Hacking – CSC Danmark (Rigspolitiet)

Company

CSC Danmark (Rigspolitiet)

Sector

Public Sector / IT Outsourcing

Actor

Gottfrid Svartholm Warg + Danish co-defendant

##Description

From April to August 2012, attackers had persistent access to mainframe systems operated by CSC Danmark, which hosted central registers on behalf of Rigspolitiet. Over roughly five months they downloaded data from the police driving-licence register — including approximately 91,000 CPR numbers — and from the Schengen Information System register of wanted persons.

The case is still routinely referred to as Denmark's largest hacking case. What made it consequential was less the intrusion itself than the detection failure around it: Rigspolitiet was warned by Deloitte about security weaknesses at CSC in June 2012, received indicators from Swedish police in September 2012 and again in January 2013, and did not review that material until late February 2013. The vulnerability was not closed until 10 March 2013 — roughly seven months after the attackers had already stopped, because Gottfrid Svartholm Warg had been arrested in Cambodia.

Both defendants were convicted on 30 October 2014. Warg received three and a half years.

##Timeline

  1. 2012-04

    Intrusion into CSC mainframe systems begins

  2. 2012-06

    Deloitte warns Rigspolitiet about security weaknesses at CSC

  3. 2012-08

    Warg arrested in Cambodia; logged attacker activity ceases

  4. 2012-09

    Swedish police report indicators of a CSC breach to Danish police

  5. 2013-01

    Swedish police repeat the warning

  6. 2013-02

    Danish police review the Swedish material

  7. 2013-03-10

    Vulnerability at CSC closed

  8. 2013-04

    Breach disclosed publicly by Rigspolitiet

  9. 2014-10-30

    Both defendants found guilty; Warg sentenced to 3½ years

##References