UNKNOWN actors misused a private Danish company’s lawful access to the national CPR register to pull personal data for about 8.8 million people. The Central Person Register (CPR) holds roughly 11 million records, including current residents, deceased individuals and emigrants. The authorities confirm that names, addresses and CPR numbers were exposed for about 8.8 million records, though some with name/address protection were excluded.
Officials caution that the figure is preliminary and may be refined as the investigation proceeds. The breach was not a conventional hack of government systems but a misuse of legitimate access provided to a private firm under Section 38 of the CPR Act, which normally covers only individuals already identified by the company.
Denmark’s CPR administration cut off the private company’s access and, with other agencies and specialists, is mapping the full sequence of events. A police investigation is in its early stages, and the case has been reported to Datatilsynet, the Danish Data Protection Agency. The incident prompts heightened vigilance for social engineering, phishing and contact-centre scams that might abuse a real name, address and CPR number to impersonate legitimate institutions.
Practical guidance issued includes never sharing passwords, verifying unexpected contacts via official channels, and consulting sikkerdigital[.]dk. The minister for Research, Education and Digitalisation has ordered a thorough security review of the CPR system and emphasised that citizens should be vigilant as investigations continue.