Denmark Data Breach Exposes Personal Records of 8.8 Million People
Denmark's Central Population Register (CPR) suffered a data breach exposing personal records of 8.8 million individuals, including names and CPR numbers, through misuse of a private company's lawful access.

Denmark has confirmed a significant data breach impacting its Central Population Register (CPR), a national database containing personal information. The incident, which occurred in September, led to unauthorized access to the records of approximately 8.8 million individuals. The exposed data includes names, addresses, and crucially, CPR numbers, which are unique personal identification numbers in Denmark. While Denmark's population is around six million, the register holds more records due to inclusions of former residents and deceased individuals.
The breach was not the result of a software vulnerability in the CPR system itself. Instead, attackers exploited a legitimate access channel by misusing the lawful access granted to a private Danish company. This company, whose identity has not been disclosed, was permitted to query the CPR system under specific conditions outlined in Denmark's Civil Registration Act. Investigators are still determining how the attackers gained control of or leveraged this company's access, leaving the initial entry vector unknown.
Under Section 38 of the Civil Registration Act, private entities can access certain CPR information for defined groups if they have a legitimate interest and comply with data protection regulations. This access is not unrestricted. Authorities are actively investigating the extent of the misuse and whether the scope of the breach might change as more information comes to light.
Officials became aware of unusual activity on October 2, 2026, and by the following weekend, confirmed the unauthorized access. The company's access was immediately revoked, and cybersecurity specialists were brought in to assess the damage. The Danish Data Protection Authority has been notified, and the police are conducting a parallel investigation.
Research, Education and Digitalization Minister Christina Egelund has described the incident as "deeply serious" and has initiated a comprehensive security review of the CPR system. While preventive measures are reportedly underway, their technical details have not been released. Notably, the review confirmed that records of individuals with name and address protection were not part of the unauthorized access, though this does not guarantee that all data fields for these individuals remained unaffected.
The compromised personal data, particularly CPR numbers, poses significant risks for identity theft and fraud. Danish authorities have issued warnings to residents, urging them to be vigilant against phishing attempts. They emphasize that even if a caller or email sender possesses personal details like name, address, and CPR number, it does not validate their legitimacy. Citizens are advised to seek official guidance through resources like Sikkerdigital or the Cyberhotline.
The full circumstances of the breach and the identity of the perpetrators remain under investigation. This incident highlights the persistent challenges in securing sensitive personal data, even when access is granted through legitimate, albeit misused, channels. The scale of the breach underscores the critical importance of robust oversight and security protocols for any entity granted access to national population registers.
This new report from The Record indicates that the data breach at Denmark's national population register was caused by unauthorized users gaining access to the system. While the previous report mentioned misuse of a private company's lawful access, this article focuses on the direct unauthorized access to the register itself, prompting an ongoing investigation into the full scope and impact of the incident.