databreaches.net 6 Oct 2026, 12:00 UTC

Danish Population Database Breach Exposes CPR Numbers of 8.8 Million

RESCANA’S post on 6 October 2026 reports that Danish authorities disclosed a cyberattack impacting the Central Person Register (CPR), Denmark’s national population database. Attackers abused a legitimate company account to access the names, addresses, and CPR numbers of about 8.8 million individuals, including current residents, former residents, and deceased persons. The breach lasted around 10 days in September 2026 and was detected after a surge in automated queries triggered an internal investigation. Notably, data disclosed did not include the names and addresses of people with name-and-address protection status.

Authorities have suspended the implicated company’s access, notified Datatilsynet (the Danish Data Protection Agency), and initiated a police investigation. The incident highlights risks inherent in centralised population databases and third-party access, with potential long-term implications for identity theft and fraud due to exposure of lifelong identifiers. In response, public advisories and extended digital security hotline hours have been put in place to assist affected individuals.

The report emphasises that the information is drawn from verified primary sources, avoiding speculation, and cautions that the breach could have broad implications for trust in national data systems and future vendor access controls.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline