Denmark Investigates Central Population Registry Breach Exposing 8.8 Million Citizen Records
Attackers accessed names, addresses, and national identification numbers by exploiting a private company's legitimate access to the government database. The breach affects roughly 80 percent of the registry, including current residents, emigrants, and deceased individuals.
By Wei Zhang
On the evening of October 2, an employee administering Denmark's Central Person Register noticed irregular automated search activity moving through the system. By the end of the weekend, the scale of the anomaly became clear: unauthorized parties had extracted the names, addresses, and national identification numbers of approximately 8.8 million people.[1][2]
The breach exposes the core of Denmark's highly digitized public infrastructure, affecting roughly 80 percent of the 11 million records held in the national database. Because the registry retains historical data, the compromised records include current residents, citizens who have emigrated, and deceased individuals.[1][3]
Denmark's current population stands at just over six million, meaning the exposure covers essentially every living resident who has not explicitly opted out of standard data sharing. The attackers did not breach the government's own servers directly, but instead bypassed central defenses by exploiting a trusted third party.[2][3]
According to the Ministry of Research, Education and Digitalisation, the perpetrators misused the legitimate access credentials of an unnamed private Danish company. Under Danish law, private entities with a demonstrated legitimate interest can query the registry to verify customer identities.[1][3]
The unauthorized access remained active for approximately ten days throughout September 2026 before the administration detected the abnormal volume of queries. The attackers reportedly used automated lookups to brute-force and confirm valid CPR numbers, pulling the associated personal details for each confirmed hit.[2][4]
Investigating the third-party compromise
The government immediately revoked the compromised company's access to the database and notified Datatilsynet, the Danish Data Protection Agency. Police have launched a formal investigation into the intrusion, though authorities have not yet identified a suspect or detailed how the company's systems were initially breached.[1][5]
Digitalization Minister Christina Egelund addressed the breach on October 5, confirming that she had briefed the Folketing's Business and Digitalisation Committee. She emphasized that the government is treating the exposure as a critical failure of the data-sharing framework.[3][5]
"This is a deeply serious incident," Egelund said in a public statement following the disclosure. "Together with all relevant authorities, we are in the process of mapping the entire extent of the incident."[3][5]
Egelund also announced immediate operational changes to prevent a recurrence while the investigation proceeds. "We have already launched initiatives in relation to CPR to prevent similar incidents," she said. "I have also asked for a thorough security review of the CPR system."[3][5]
The ministry confirmed that the attackers stayed within the technical boundaries of the information that private companies are legally permitted to retrieve. Consequently, individuals who had previously registered for strict name and address protection were not included in the exposed dataset.[1][4]
The lifelong identifier
The exposed CPR number is a ten-digit sequence assigned to every resident, typically combining their date of birth with four unique trailing digits. It functions as the universal key for Danish society, linking a person to their tax records, healthcare history, and banking services.[1][2]
While a CPR number alone cannot authorize transactions that require the national MitID two-factor authentication system, it provides a powerful foundation for targeted social engineering. Armed with a citizen's exact address and identification number, scammers can craft highly convincing communications posing as government officials or bank representatives.[2][4]
To mitigate the immediate fallout, the government has extended the operating hours of its digital security hotline, keeping it open from 8:00 a.m. to midnight. Officials are urging citizens to remain vigilant and to refuse any requests for passwords or secondary authentication codes over the phone.[1][5]
The ministry explicitly warned that residents should not trust callers simply because they can recite accurate personal details. Even if a caller knows a target's name, physical address, and full CPR number, authorities emphasize that legitimate institutions will never ask for login credentials.[1][3]
Supply chain vulnerabilities
The breach highlights a structural vulnerability in centralized national databases that provision direct access to private sector partners. When a single supplier's account is compromised, the government's internal security controls are effectively bypassed, turning a lawful connection into a massive data exposure.[1][4]
Cybersecurity analysts note that this vector—abusing legitimate API access rather than breaking through firewalls—is becoming increasingly common for large-scale data theft. The attackers simply authenticated as the trusted company and requested the data exactly as the system was designed to provide it.[2][5]
The incident is the most significant exposure of the CPR system since 2015, when unencrypted physical discs containing five million records were mistakenly delivered to a foreign visa center. In that case, authorities concluded the data was recovered before it could be copied or misused.[1][2]
This time, the data has definitively left the system, though it remains unclear whether the attackers intend to sell the database on criminal forums or exploit it directly. The Danish Data Protection Agency is currently assessing how the private company managed the personal data it was authorized to access.[3][5]
The agency's review will likely scrutinize whether the company implemented adequate safeguards, such as rate-limiting or anomaly detection, to prevent its credentials from being used for bulk extraction. Under the General Data Protection Regulation, the company could face significant penalties if it failed to secure its connection.[1][4]
Key points
- Hackers extracted the names, addresses, and national identification numbers of 8.8 million people from Denmark's Central Person Register.
- The attackers bypassed government defenses by compromising a private Danish company that held legitimate access to the database.
- The exposed records include current residents, emigrants, and deceased individuals, covering roughly 80 percent of the registry.
- Digitalization Minister Christina Egelund ordered a comprehensive security review and warned citizens to remain alert for targeted fraud.
Open questions
- The identity of the attackers and their ultimate motive for extracting the population data remains unknown.
- Authorities have not disclosed the name of the private company whose systems were compromised to access the registry.
- It is unclear exactly how the attackers breached the private company's internal network to hijack its legitimate access credentials.
Timeline
September 2026
Unauthorized parties begin using a private company's legitimate access to query the Central Person Register.
October 2, 2026
An employee administering the CPR system detects irregular automated search activity.
October 4, 2026
The CPR administration determines the scale of the breach and notifies the Danish Data Protection Agency.
October 5, 2026
The Ministry of Research, Education and Digitalisation publicly discloses the incident and confirms a police investigation.
- Government Authorities
- State officials emphasize that the breach stemmed from a third-party failure rather than a flaw in the national registry's core architecture.
- Cybersecurity Analysts
- Security professionals point to the incident as a textbook example of supply-chain vulnerability in centralized systems.
- Privacy Advocates
- Privacy defenders warn of the permanent risks created when immutable identifiers are exposed at a population scale.
Perspectives this story doesn't cover
- The unnamed private company whose access was compromised
- Financial institutions that rely on CPR numbers for customer verification
Sources
[1]The RecordPrivacy AdvocatesData breach at Denmark's national population register exposes 8.8 million people
Read on The Record →
[2]BleepingComputerCybersecurity AnalystsDenmark population registry data breach affects 8.8 million people
Read on BleepingComputer →
[3]The Hacker NewsGovernment AuthoritiesDenmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Read on The Hacker News →
[4]SecurityOnlineCybersecurity AnalystsDenmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People
Read on SecurityOnline →
[5]GBHackersGovernment AuthoritiesDenmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records
Read on GBHackers →
More in Technology
See all →OAuth 2.0
The Six Steps of the OAuth 2.0 Authorization Code Flow with PKCE
4 sources
Core Vulnerability
WordPress Patches Critical Core Vulnerability as Attackers Exploit Flaw Within Hours
5 sources
Zero-Day Exploits
Chinese State-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
4 sources
Maritime Security
FBI and Coast Guard Board US-Bound Oil Tankers Following Suspected Cyberattacks
5 sources
Comments
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns, free every day.




