Oct 6 / Latest News

Denmark’s Central Population Register Breach Exposes CPR Data of 8.8 Million People

A data breach at Denmark’s Central Population Register (CPR) exposed names, addresses, and CPR numbers belonging to about 8.8 million people, including current residents, deceased individuals, and citizens who have moved abroad. The CPR is Denmark’s national register and its 10‑digit identifier is used across healthcare, banking, taxation, and public services.

The CPR administration detected irregular activity on Friday, October 2, 2026, and discovered over the weekend that unauthorized parties had accessed the system throughout September. The Danish Data Protection Agency (Datatilsynet) was notified on October 4, and the Ministry of Research, Education and Digitalisation publicly disclosed the incident on October 5. Minister Christina Egelund called the breach “deeply serious” and ordered a full security review of the CPR system.

Attackers obtained data by misusing a private Danish company’s legitimate access to search the CPR system. According to officials, the unauthorized queries stayed within the limits of what private companies are normally allowed to retrieve. The CPR holds roughly 11 million records, meaning the breach covered about 80% of the register. Individuals with name‑and‑address protection were not included. The company’s access has been terminated, and police are investigating how the unauthorized parties gained entry and whether the stolen data has been retained or used.

Datatilsynet said a very large number of automated lookups were made to identify valid CPR numbers. It has opened a case to determine what happened, how it was possible, and who is responsible for processing the personal data involved. The ministry warns that the stolen information could be used for fraud attempts and advises citizens never to share passwords, MitID details, one‑time codes, or card information, even if a caller or sender appears to know their CPR number.

Citizens are encouraged to follow guidance at sikkerdigital.dk, including being alert to unexpected messages, avoiding suspicious links, and setting a credit warning on borger.dk. The government’s Cyberhotline for digital security (+45 33 37 00 37) has extended hours to assist affected individuals. A credit warning signals to companies that extra identity checks should be performed before issuing loans or credit.

The ministry has begun implementing measures to prevent similar incidents and is assessing whether any individuals may eventually need new CPR numbers. Datatilsynet continues to examine the breach, the security controls around company access, and the broader implications for Denmark’s national identity infrastructure.