DENMARK’S Central Person Register (CPR), the national civil registration system that holds data on around 11 million people, has disclosed a data breach affecting approximately 8.8 million registered individuals, including living, emigrated and deceased residents. Hackers allegedly exploited a Danish company’s legitimate access to the CPR to exfiltrate personal information such as names, addresses and CPR numbers (the Danish equivalent of Social Security numbers). The incident was detected in September after abnormal activity in the CPR systems, with discovery reported over the following weekend.
CPR says the breach did not impact individuals who had opted for the name and address protection feature. In response, CPR terminated the private company’s access, notified the Danish Data Protection Agency, and launched a formal investigation with police and other authorities. The organisation emphasised that it cannot name the threat actor behind the breach. Members of the public are advised to be wary of unsolicited communications requesting personal data, passwords, or other sensitive information.
CPR also stated it would review its security policies and strengthen protections to prevent a recurrence. The article notes that the data accessed included basic identifying details, but stops short of confirming how the information might be used or whether any accounts were compromised. The breach is being treated as a serious incident with ongoing investigations and policy reviews.