Denmark says 8.8 million people's records accessed in national population register breach
Danish authorities said unauthorized parties misused a private company's legitimate access to the Central Person Register to pull names, addresses and CPR numbers for about 8.8 million people.
At a glance
- Roughly 8.8 million of the 11 million records in Denmark's Central Person Register were accessed, including people who have emigrated or died
- Attackers abused a private Danish company's legitimate register access to run automated searches for valid CPR numbers
- Irregular activity was spotted on the evening of Friday 2 October; the access itself happened during September
- The company's access has been revoked and data protection authority Datatilsynet has been notified; no suspect has been identified
Denmark's government announced on 5 October 2026 that unauthorized parties accessed records belonging to approximately 8.8 million people in the Central Person Register (CPR), the national database that underpins almost every public and private service in the country. According to the announcement reported by The Record and CyberInsider, the attackers did not break the system open: they misused the legitimate register access held by a private Danish company to run automated searches for valid CPR numbers.
What happened
CyberInsider reports that administrators noticed irregular activity in the CPR system on the evening of Friday, 2 October 2026, while the unauthorized access itself took place during September. Investigators worked through the following weekend and established that information on roughly 8.8 million registered individuals had been pulled from the register before the announcement was made public on Monday.
The Record notes that the CPR currently holds records on about 11 million people, a figure well above Denmark's population because the register also covers people who have moved abroad and people who have died. The share of records touched is therefore close to the entire register. According to CyberInsider, individuals who have registered name and address protection were excluded from the data that was accessed.
Technical details
Both outlets report that the access was carried out through a private Danish company that holds authorised lookup rights in the register. Neither the company's name nor the way the attackers obtained the ability to use that access has been disclosed. The searches were automated and targeted valid CPR numbers, which suggests the operation was aimed at harvesting records in bulk rather than at a specific individual.
The CPR number is a ten-digit identifier that begins with the holder's date of birth; The Record compares its role in Danish life to that of the Social Security number in the United States. The data confirmed as accessed consists of names, addresses and CPR numbers. The police investigation remains at an early stage and, according to CyberInsider, no responsible party has been identified.
Who is affected
Because the register is close to universal, the practical assumption for anyone who has been registered in Denmark is that their name, address and CPR number may be in the attackers' hands. The CPR administration has revoked the company's access, notified Danish data protection authority Datatilsynet and is investigating alongside specialists and other authorities.
Christina Egelund, Minister for Research, Education and Digitalisation, called the incident "deeply serious" and ordered a thorough security review of the CPR system, with preventive measures introduced but not detailed publicly. Egelund also briefed the Danish parliament's business and digitalisation committee.
What to do
The official guidance is built around the fact that a CPR number is widely treated as proof of identity over the phone. Authorities advised that people should not disclose this information, even if a caller already appears to know their name, address and CPR number, and should refuse any telephone, email or similar request for passwords or confidential information. Denmark's digital security hotline has extended its hours to 8 a.m. until midnight to handle the volume of enquiries.
Organisations that accept a CPR number as an authentication factor should treat it as public going forward and move to verification methods that do not rely on static identifiers. The incident is also a reminder that third-party access rights to a central register are part of that register's attack surface: access scope, query rate limits and anomaly monitoring on partner accounts matter as much as the security of the register itself.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



