Data breach at Denmark’s population register exposes 8.8 million people
Denmark's Central Population Register breach exposed names, addresses, and CPR numbers of 8.8 million people via misused company access.
Attackers obtained names, addresses and CPR numbers of 8.8 million people—roughly 80% of Denmark's 11-million-record national register—by misusing a private Danish company's legitimate search access during September 2026. CPR administration learned of irregular activity on October 2 and notified the Danish Data Protection Agency on October 4, with police investigating and the company's access cut off. Minister Christina Egelund informed Parliament and ordered a thorough security review. People registered with name and address protection were not exposed, and officials warn the data could enable convincing fraud attempts.