HACKERS gained access to Denmark’s national population register through a third‑party company that has legal access to the registry, rather than breaking directly into government systems. The breach exposes names, addresses and CPR numbers for 8.8 million people. The CPR number is a unique identifier akin to a social security number and is used for services such as banking, healthcare and taxes in Denmark.
The registry covers people living in Denmark as well as those who have died or moved abroad, which is why the database holds about 11 million records in total. The digital affairs minister, Christina Egelund, described the incident as “an extremely serious” breach and said authorities were working with relevant agencies to map out the full extent of the impact.
At present, investigators have not identified the perpetrators, but the entry point is clear: the attackers abused the third party’s access rather than compromising the central registry directly, and alarmingly, the ministry said the third party’s access has not yet been revoked. This raises concerns that the same access used in the attack could still be active. The breach highlights the significant risk posed by third‑party vendors when dealing with highly sensitive government data.
Beyond privacy implications, there are practical dangers of identity fraud and potential national security concerns, given how such data can support espionage, social engineering, or influence operations. The incident underscores the need for tighter oversight of external access to critical public records and rapid containment steps in the wake of discoveries.