TECHNOLOGY
Breach at Danish Civil Registration System Exposes Data of 8.8 Million People
Denmark's CPR administration says attackers abused a private company's legitimate access to the national civil registry, exposing names, addresses and CPR numbers of about 8.8 million registered citizens, living and deceased.
Image: Znaki · Uploaded by IntraGoals — usage rights confirmed
Denmark's Central Register of Persons (CPR) has confirmed a serious security breach after unauthorized individuals exploited a private Danish company's legitimate access to the registry to obtain personal data on roughly 8.8 million people.
The CPR administration said the attackers did not create a new vulnerability but instead abused access rights legally granted to a company under Danish law, which permits private firms with a legitimate interest to query the register for limited, specific information about individuals they have already identified. Through that access, unauthorized parties were able to extract names, addresses and CPR numbers — Denmark's unique personal identification numbers — belonging to both living and deceased citizens, as well as Danes who have moved abroad.
According to the authority, the CPR system currently holds records on about 11 million people in total. Names and addresses of individuals who had opted into Denmark's name and address protection scheme were not affected, officials said.
The CPR administration first noticed irregular activity within the system on the evening of Friday, October 2, 2026, and by the following weekend had determined that the access dated back to activity occurring in September. The company's access to the register has since been revoked, and officials are working with external specialists and other authorities to reconstruct exactly what happened.
The breach has been reported to the Danish Data Protection Agency, and police are now investigating alongside relevant authorities. Officials cautioned that the case is in its early stages and that details could still change as the investigation continues. It remains unclear who is responsible.
Minister of Research, Education and Digitalisation Christina Egelund called the incident "deeply serious" and said she has briefed the Danish Parliament's Business and Digitalisation Committee. She said the government has already begun measures to prevent similar incidents and has ordered a full security review of the CPR system.
Citizens are being urged not to share passwords, CPR numbers or other confidential information over the phone or by email, even if the person contacting them appears to already know their name, address or CPR number — information that may now be more widely available to fraudsters as a result of the breach.
The government is directing concerned citizens to the sikkerdigital.dk website and a dedicated cyber hotline, +45 33 37 00 37, which has extended its hours to run from 8 a.m. to midnight in the days following the disclosure.
Under Denmark's Civil Registration Act, private companies with a legitimate interest are permitted to request limited CPR information about specific individuals they identify in advance, provided they also meet requirements under GDPR and Danish data protection law. Authorities have not said how the company's access was compromised or whether the company itself was targeted directly.