www.infosecurity-magazine.com 7 Oct 2026, 08:20 UTC

Danish CPR Breach Exposes Personal Data of 8.8 Million People

CyberSIXT Evidence Panel Source marked as original reporting

A Danish data breach has exposed personal details for about 8.8 million people, highlighting the cyber risk embedded in national supply chains. The Central Register of Persons (CPR) stores basic information such as names, addresses and CPR numbers, and the incident unfolded in September when unauthorized individuals used a private Danish company’s legal access to query the CPR system.

The CPR administration first detected irregular activity three days before the public notice, and the breach affected residents, departed, and deceased individuals alike.

Experts say the breach underscores the dangers of highly centralised national databases that are accessible through private suppliers. Dray Agha of Huntress warned that a compromised supplier account can bypass core security controls and turn a legitimate connection into widespread data exposure. Real-time monitoring of third-party access is now being called for, along with stricter limits on what external partners can view.

Michael Centrella of SecurityScorecard emphasised continuous monitoring rather than annual reviews, and Nathan Davies-Webb of Acumen Cyber urged measures such as stronger authentication, shorter sessions, rate limiting and a baseline of normal behaviour.

The government also urged citizens to be vigilant against phishing, advising verification through official channels and the use of unique passwords managed in a password manager, with organisations urged to apply strict supplier reviews and incident response rehearsals.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline