Denmark is investigating one of its largest personal-data breaches after unauthorised individuals gained access to names, addresses and national identification numbers belonging to around 8.8 million people registered in the country’s central population database.
The incident involved Denmark’s Central Person Register, known as the CPR, which sits at the heart of the country’s highly digitised public-sector system.
Authorities said the attackers did not simply break into the CPR database directly. Instead, they allegedly abused the legitimate access of a private Danish company that was authorised to search information in the register.
The company’s access has since been blocked, police have opened an investigation and the Danish government has ordered a wider security review of the system.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
8.8 Million Records Exposed
The affected figure is approximately 8.8 million registered people.
That is larger than Denmark’s current population because the CPR system contains roughly 11 million records in total.
Those records include people currently living in Denmark, citizens who have moved abroad and people who have died.
The exposed information includes names, addresses and CPR numbers.
A CPR number is Denmark’s unique personal identification number and is widely used when interacting with government agencies, banks, healthcare providers and other institutions.
Attackers Allegedly Used Company’s Legitimate Access
The Danish Ministry of Science, Higher Education and Digital Affairs said the incident involved misuse of a private company’s lawful ability to search the CPR system.
Under Danish law, private companies with a legitimate interest can obtain certain information from the population register when specific conditions are met.
Authorities say unidentified individuals used one such company’s access to carry out unauthorised searches at large scale.
The ministry has not publicly identified the company.
It is also not yet clear whether the company itself was hacked, whether credentials were stolen or whether another method was used to abuse its access.
Automated Searches Used to Identify Valid CPR Numbers
Denmark’s Data Protection Agency said it received a breach notification on October 4.
According to the notification, a very large number of automated searches were carried out against the CPR system in an attempt to identify valid CPR numbers.
Cybersecurity outlet BleepingComputer described the method as a form of automated enumeration or brute-force searching, where attackers repeatedly query a system to discover valid records.
The precise technical method remains under investigation.
Incident Took Place During September
The suspicious activity occurred during September 2026.
CPR administrators first became aware of irregular behaviour on the evening of October 2.
During the following weekend, authorities established that unauthorised users had gained access to information associated with approximately 8.8 million registered individuals.
The government disclosed the incident publicly on October 5.
Police and other authorities are still trying to determine who was responsible.
People With Name and Address Protection Were Partly Shielded
The government said the unauthorised access did not expose the names and addresses of people who had formally registered for name-and-address protection.
Denmark’s CPR system allows people in certain circumstances to restrict access to those details.
Government statistics show more than 152,000 such protections were active as of October 1.
However, authorities have not yet publicly provided a complete technical breakdown of exactly which fields were accessible for every affected category of person.
Minister Calls Incident ‘Deeply Serious’
Denmark’s Minister for Science, Higher Education and Digital Affairs, Christina Egelund, described the breach as a deeply serious incident.
She said Parliament’s Business and Digitalisation Committee had been informed and that a comprehensive security review of the CPR system had been ordered.
The government said additional measures have already been introduced to reduce the risk of similar abuse.
The exact nature of those protections has not been publicly detailed.
Why CPR Numbers Matter
A CPR number is a 10-digit identifier used extensively across Danish society.
It helps distinguish individuals when dealing with government agencies, healthcare systems and financial institutions.
The number itself does not automatically provide access to someone’s bank account or digital identity.
But when combined with a person’s name, address and other information, it can make phishing, impersonation and social-engineering attacks far more convincing.
That is why Danish authorities are warning people to be particularly cautious about unsolicited calls and emails following the breach.
Government Warns of Follow-On Fraud
The ministry specifically warned residents not to disclose passwords or confidential information simply because a caller appears to know their name, address or CPR number.
Attackers frequently use genuine leaked information to make fraudulent communications appear legitimate.
A criminal who already knows personal information may claim to represent a bank, government office or other trusted organisation and then ask for passwords, verification codes or payment information.
The breach therefore creates risks even if the exposed database itself contained no banking passwords.
Denmark Opens Cyber Hotline for Affected People
The Danish government has expanded the operating hours of its national cyber-security hotline following the breach.
Authorities are also directing people to official digital-safety resources for advice.
The focus is currently on preventing follow-on phishing, impersonation and identity-based fraud while investigators establish exactly how the access occurred.
Private Access to Government Databases Under Scrutiny
The incident raises broader questions about how companies are allowed to access national identity databases.
Denmark’s CPR Act permits certain private organisations with a legitimate interest to access specified information.
That arrangement is useful for legitimate commercial and administrative purposes.
But the breach shows how authorised access itself can become a security weakness if credentials, systems or search functionality are abused.
The attack therefore appears to be as much an access-control problem as a conventional database breach.
Denmark Orders Wider CPR Security Review
Egelund has asked for a comprehensive security examination of the CPR infrastructure.
Authorities are expected to examine how the company’s access was abused, whether automated-query limits were adequate and whether additional safeguards are required for organisations authorised to search the register.
The Danish Data Protection Agency has opened its own examination into what happened, how the incident became possible and which organisation bears responsibility for the relevant processing of personal information.
Because that investigation has only just begun, the regulator said it cannot yet reach conclusions about responsibility.
No Attribution Yet
Authorities have not identified the people behind the incident.
There is also no public evidence at this stage linking the breach to a government, organised cybercrime group or known hacking organisation.
The Danish government has said the factual circumstances are still being mapped and that some figures or details may change as the investigation develops.
What this means for you
Large identity-data breaches often become most dangerous after the initial incident, when criminals use real personal information to make phishing calls and messages more believable. Never provide passwords, banking credentials or verification codes simply because someone contacting you already knows your name, address or official identification number.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics