Skip to main content
Data PrivacyCentral Person Register· 5 min read· in Technology

Denmark Investigates Central Population Registry Breach Exposing 8.8 Million Citizen Records

Attackers accessed names, addresses, and national identification numbers by exploiting a private company's legitimate access to the government database. The breach affects roughly 80 percent of the registry, including current residents, emigrants, and deceased individuals.

By Wei Zhang

On the evening of October 2, an employee administering Denmark's Central Person Register noticed irregular automated search activity moving through the system. By the end of the weekend, the scale of the anomaly became clear: unauthorized parties had extracted the names, addresses, and national identification numbers of approximately 8.8 million people.[1][2]

The breach exposes the core of Denmark's highly digitized public infrastructure, affecting roughly 80 percent of the 11 million records held in the national database. Because the registry retains historical data, the compromised records include current residents, citizens who have emigrated, and deceased individuals.[1][3]

Denmark's current population stands at just over six million, meaning the exposure covers essentially every living resident who has not explicitly opted out of standard data sharing. The attackers did not breach the government's own servers directly, but instead bypassed central defenses by exploiting a trusted third party.[2][3]

According to the Ministry of Research, Education and Digitalisation, the perpetrators misused the legitimate access credentials of an unnamed private Danish company. Under Danish law, private entities with a demonstrated legitimate interest can query the registry to verify customer identities.[1][3]

The unauthorized access remained active for approximately ten days throughout September 2026 before the administration detected the abnormal volume of queries. The attackers reportedly used automated lookups to brute-force and confirm valid CPR numbers, pulling the associated personal details for each confirmed hit.[2][4]

The breach exposed records for roughly 80 percent of the individuals logged in the national registry.

Investigating the third-party compromise

The government immediately revoked the compromised company's access to the database and notified Datatilsynet, the Danish Data Protection Agency. Police have launched a formal investigation into the intrusion, though authorities have not yet identified a suspect or detailed how the company's systems were initially breached.[1][5]

Digitalization Minister Christina Egelund addressed the breach on October 5, confirming that she had briefed the Folketing's Business and Digitalisation Committee. She emphasized that the government is treating the exposure as a critical failure of the data-sharing framework.[3][5]

"This is a deeply serious incident," Egelund said in a public statement following the disclosure. "Together with all relevant authorities, we are in the process of mapping the entire extent of the incident."[3][5]

Egelund also announced immediate operational changes to prevent a recurrence while the investigation proceeds. "We have already launched initiatives in relation to CPR to prevent similar incidents," she said. "I have also asked for a thorough security review of the CPR system."[3][5]

The ministry confirmed that the attackers stayed within the technical boundaries of the information that private companies are legally permitted to retrieve. Consequently, individuals who had previously registered for strict name and address protection were not included in the exposed dataset.[1][4]

The lifelong identifier

The exposed CPR number is a ten-digit sequence assigned to every resident, typically combining their date of birth with four unique trailing digits. It functions as the universal key for Danish society, linking a person to their tax records, healthcare history, and banking services.[1][2]

The unauthorized access continued for approximately ten days before registry administrators detected the anomaly.

While a CPR number alone cannot authorize transactions that require the national MitID two-factor authentication system, it provides a powerful foundation for targeted social engineering. Armed with a citizen's exact address and identification number, scammers can craft highly convincing communications posing as government officials or bank representatives.[2][4]

To mitigate the immediate fallout, the government has extended the operating hours of its digital security hotline, keeping it open from 8:00 a.m. to midnight. Officials are urging citizens to remain vigilant and to refuse any requests for passwords or secondary authentication codes over the phone.[1][5]

The ministry explicitly warned that residents should not trust callers simply because they can recite accurate personal details. Even if a caller knows a target's name, physical address, and full CPR number, authorities emphasize that legitimate institutions will never ask for login credentials.[1][3]

Supply chain vulnerabilities

The breach highlights a structural vulnerability in centralized national databases that provision direct access to private sector partners. When a single supplier's account is compromised, the government's internal security controls are effectively bypassed, turning a lawful connection into a massive data exposure.[1][4]

Cybersecurity analysts note that this vector—abusing legitimate API access rather than breaking through firewalls—is becoming increasingly common for large-scale data theft. The attackers simply authenticated as the trusted company and requested the data exactly as the system was designed to provide it.[2][5]

Illustration: Authorities have urged residents to remain vigilant against targeted social engineering attempts using the stolen data.

The incident is the most significant exposure of the CPR system since 2015, when unencrypted physical discs containing five million records were mistakenly delivered to a foreign visa center. In that case, authorities concluded the data was recovered before it could be copied or misused.[1][2]

This time, the data has definitively left the system, though it remains unclear whether the attackers intend to sell the database on criminal forums or exploit it directly. The Danish Data Protection Agency is currently assessing how the private company managed the personal data it was authorized to access.[3][5]

The agency's review will likely scrutinize whether the company implemented adequate safeguards, such as rate-limiting or anomaly detection, to prevent its credentials from being used for bulk extraction. Under the General Data Protection Regulation, the company could face significant penalties if it failed to secure its connection.[1][4]

For now, the focus remains on securing the registry and tracing the digital footprint left by the automated queries. Until the police investigation concludes, the full mechanics of the initial corporate compromise will remain shielded from public view.[3][5]

Key points

  • Hackers extracted the names, addresses, and national identification numbers of 8.8 million people from Denmark's Central Person Register.
  • The attackers bypassed government defenses by compromising a private Danish company that held legitimate access to the database.
  • The exposed records include current residents, emigrants, and deceased individuals, covering roughly 80 percent of the registry.
  • Digitalization Minister Christina Egelund ordered a comprehensive security review and warned citizens to remain alert for targeted fraud.

Open questions

  • The identity of the attackers and their ultimate motive for extracting the population data remains unknown.
  • Authorities have not disclosed the name of the private company whose systems were compromised to access the registry.
  • It is unclear exactly how the attackers breached the private company's internal network to hijack its legitimate access credentials.

Timeline

  1. September 2026

    Unauthorized parties begin using a private company's legitimate access to query the Central Person Register.

  2. October 2, 2026

    An employee administering the CPR system detects irregular automated search activity.

  3. October 4, 2026

    The CPR administration determines the scale of the breach and notifies the Danish Data Protection Agency.

  4. October 5, 2026

    The Ministry of Research, Education and Digitalisation publicly discloses the incident and confirms a police investigation.

Government Authorities 40%Cybersecurity Analysts 35%Privacy Advocates 25%
Government Authorities
State officials emphasize that the breach stemmed from a third-party failure rather than a flaw in the national registry's core architecture.
Cybersecurity Analysts
Security professionals point to the incident as a textbook example of supply-chain vulnerability in centralized systems.
Privacy Advocates
Privacy defenders warn of the permanent risks created when immutable identifiers are exposed at a population scale.

Perspectives this story doesn't cover

  • The unnamed private company whose access was compromised
  • Financial institutions that rely on CPR numbers for customer verification

Sources

Source coverage

5 outlets

3 viewpoints surfaced

Government Authorities 40%Cybersecurity Analysts 35%Privacy Advocates 25%
  1. [1]The RecordPrivacy Advocates

    Data breach at Denmark's national population register exposes 8.8 million people

    Read on The Record →
  2. [2]BleepingComputerCybersecurity Analysts

    Denmark population registry data breach affects 8.8 million people

    Read on BleepingComputer →
  3. [3]The Hacker NewsGovernment Authorities

    Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

    Read on The Hacker News →
  4. [4]SecurityOnlineCybersecurity Analysts

    Denmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People

    Read on SecurityOnline →
  5. [5]GBHackersGovernment Authorities

    Denmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records

    Read on GBHackers →

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns, free every day.