Denmark Data Breach Exposes Personal Records of 8.8 Million People
Denmark says unauthorized access exposed names, addresses, and CPR numbers for about 8.8 million people.
Denmark confirmed that unauthorized parties accessed Central Population Register records for about 8.8 million people, including names, addresses, and CPR numbers. The register holds about 11 million people, above Denmark's roughly six million residents, because it includes people abroad and the deceased. Attackers misused a named-undisclosed private company's lawful search access during September; officials did not identify a software flaw or threat group. Unusual activity was found on October 2, the company's access was blocked, the Data Protection Authority was notified, and police are investigating.
- About 8.8 million CPR records exposed, including national ID numbers
- Attackers misused a private company's approved register access
- No company name, threat group, or vulnerability was identified
- Unusual activity was found October 2 and that access was blocked
- Protected name-and-address records were not in the accessed set
Full article611 words · extracted from cybersecuritynews.com · click to collapse
Denmark has confirmed a major data breach involving its Central Population Register, known as CPR, after unauthorized parties accessed personal records belonging to about 8.8 million people. The exposed information includes names, addresses, and CPR numbers, according to an official statement published on October 5, 2026.
The figure exceeds Denmark’s population of roughly six million because the register also holds records of people who have moved abroad and those who have died. Officials said the CPR system currently contains approximately 11 million registered people, meaning the incident affected a large share of its records.
How Attackers Accessed CPR Records
The attackers misused a private Danish company’s lawful access to search the CPR system during September. Authorities have not described how the unauthorized parties obtained or used that access, leaving the initial entry method unknown.
The confirmed route is important: this was misuse of an approved company connection, not a publicly confirmed software flaw in the register. The ministry has not disclosed the company’s name, linked the incident to a known threat group, or identified a specific vulnerability.
Under Section 38 of Denmark’s Civil Registration Act, private companies with a legitimate interest can receive certain CPR information about a defined group of people identified beforehand. They must also meet requirements under the General Data Protection Regulation and Denmark’s Data Protection Act.
Those rules do not provide unrestricted access to everyone’s records. Investigators are still examining how the company’s permitted access was misused on this scale and whether further findings will change the reported details.
The CPR administration became aware of unusual system behavior on Friday evening, October 2. Over the following weekend, officials established that unauthorized parties had accessed information covering approximately 8.8 million registered people.
Authorities blocked the company’s access and brought in specialists to map the incident. The administration also reported the breach to Denmark’s Data Protection Authority. Police are investigating alongside other relevant authorities, but the inquiry remains at an early stage.
Research, Education and Digitalization Minister Christina Egelund described the incident as deeply serious. She informed Parliament’s Business and Digitalization Committee and requested a thorough security review of CPR. Officials said preventive measures had already started, without detailing their technical scope.
The review found that names and addresses belonging to people registered with name and address protection were not included in the unauthorized access. This finding should not be read as confirmation that every data field for those people remained unaffected.[ufm]
Phishing Attack Risks
Names, addresses, and national identification numbers can make fraudulent messages and calls appear convincing. Cybersecurity News’ coverage of the Pentagon data breach similarly highlights the risks when personal records include identity numbers, while its phishing prevention guidance explains common warning signs.
Danish authorities warn residents not to share passwords or other confidential information through unexpected calls or emails, even when the sender already knows their name, address, and CPR number. Knowing those details does not prove that a caller represents a trusted organization.
Citizens can seek official guidance through Sikkerdigital or call the Cyberhotline for digital security at +45 33 37 00 37. The hotline has extended its opening hours to 8 a.m. through midnight in the coming days. Authorities have not yet publicly identified who carried out the breach, and the full circumstances remain under investigation.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.