Denmark has disclosed a major data breach in which unauthorised people obtained the names, addresses and personal identification numbers of about 8.8 million registered people from the country’s Central Person Register, known as the CPR. The government announced the incident on Monday, October 5. It said the intruders did not break into the register directly: they misused the legitimate access of a private Danish company.
What the government says happened
According to the official statement from the Ministry of Research, Education and Digitalisation, the CPR administration found that unauthorised individuals had obtained access to “names, addresses, CPR numbers etc.” for about 8.8 million people registered in the system. The figure covers people who are living, have emigrated or have died. The ministry’s review shows the access does not include the names and addresses of people who have chosen to register with name and address protection.
Denmark has a population of about six million, but the CPR holds records on roughly 11 million people, because it also includes the dead and those who have moved abroad.
The CPR administration has stopped the company’s access and, together with specialists and authorities, is mapping the sequence of events. It has reported the case to the Danish Data Protection Agency (Datatilsynet), and the police are investigating. The ministry said the investigation is at an early stage and that it is not yet possible to say who is behind it. It also cautioned that further mapping could change the details.
Timeline, as stated by the ministry
| When | What happened |
|---|---|
| During September | Irregular behaviour took place in the CPR system |
| Evening of Friday, October 2 | The CPR administration noticed the irregular activity |
| Over the weekend | It learned that unauthorised people had obtained data on about 8.8 million people |
| Monday, October 5 | The ministry made the incident public |
The Danish government says the incident occurred within the framework of the information private companies are allowed to access.
How a private company had access
Under section 38 of the CPR Act, private companies with a legitimate interest can receive information from the register about a larger, defined group of people whom they have already identified individually, either by CPR number, or by date of birth and name, or by name and address. The company must also be entitled to receive the data under the EU’s General Data Protection Regulation and Danish data protection law. The ministry has not said which company was involved, how the intruders obtained its access, or how a lookup service came to expose millions of records. Those are among the central questions of the investigation.
What the minister said
Christina Egelund, the minister, called it “a deeply serious incident.” She said she had informed the Danish parliament’s Business and Digitalisation Committee, that measures had already been taken to prevent similar incidents, and that she had asked for a thorough security review of the CPR system. “Together with all relevant authorities, we are in the process of mapping the full extent of the incident,” she said.
What people are being told to do
The government reminded people never to give out passwords or other confidential information in phone calls, emails or similar contacts, even if the person on the other end seems to know their name, address and CPR number. Citizens were pointed to the Danish government’s security website, sikkerdigital.dk, and to a cyber hotline on +45 33 37 00 37, which has extended opening hours of 8 a.m. to midnight for the coming days.
The main risk, as security experts quoted by Cybernews point out, is fraud: criminals who already know a person’s details can make phishing messages and calls far more convincing. Denmark relies heavily on MitID, its digital ID system with two-step authentication, and Cybernews reports that attackers cannot impersonate someone with a CPR number alone.
Why it matters beyond Denmark
The CPR number is the backbone of Denmark’s highly digitised public sector. The incident shows how a single supplier connection can turn into a national-scale exposure. “A compromised account at a single supplier can bypass an organization’s core security controls,” said Dray Agha of the security firm Huntress, adding that it can turn a legitimate connection into a massive data exposure. The lesson applies to any country that lets private firms query government identity databases, which includes India.

No responses yet