thehackernews.com 6 Oct 2026, 06:00 UTC

Denmark’s CPR Register Breach Exposes Personal Data of 8.8 Million

CyberSIXT Evidence Panel Source marked as original reporting

UNAUTHORIZED parties accessed the Central Person Register (CPR) in Denmark, exposing the names, addresses, and personal identification numbers of about 8.8 million people, including living residents, those who have moved abroad, and the deceased. The breach lasted around 10 days in September, with activity detected on 2 October after an administrator noticed unusual looking-ups.

Access originated from a private Danish company that had a lawful right to query records in the CPR, and the ministry said the data involved came from private-sector lookups rather than nationwide disclosures of protected names and addresses. The CPR administration has since cut the company’s access and reported the incident to Datatilsynet, Denmark’s data protection authority; police are investigating.

The ministry has not yet confirmed whether CPR numbers themselves were obtained for all affected individuals, and three questions remain unresolved: how the intruders gained entry to the company’s systems, whether any data were retained or misused, and the identities of those responsible. The register’s guidance states that CPR numbers help identify people but should not be used as the sole proof of identity, and that only data on individuals already known to a company may be shared.

In response, Datatilsynet is examining the incident and the minister has ordered a full security review of the CPR system. The government is directing citizens to heightened vigilance against fraud and to follow guidance on safeguarding MitID, noting that a new credit warning marker in the CPR may be issued to alert lenders.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline