Denmark is investigating a massive data breach after unauthorized individuals gained access to personal information belonging to approximately 8.8 million people in the country’s Central Person Register, known as CPR.
The exposed information includes names, addresses, and CPR numbers, Denmark’s unique personal identification numbers. The records cover not only current residents but also people who have moved abroad and those who have died, explaining why the number affected is larger than Denmark’s population.
The attackers did not directly break into the CPR system. Instead, they abused a private Danish company’s legitimate authorization to search the national database and carried out a large number of automated queries.
Denmark’s Data Protection Agency said the activity appears to have been designed to identify valid CPR numbers. Authorities have not publicly identified the company whose access was misused.
People registered with name and address protection were partially shielded from the incident. According to the government’s initial investigation, their protected names and addresses were not exposed through the unauthorized searches.
The suspicious activity took place during September and was detected by the CPR administration on October 2. The company’s access to the database has since been disabled while authorities and cybersecurity specialists investigate how the incident happened.
Denmark’s Minister for Higher Education, Research and Digitalisation, Christina Egelund, described the incident as extremely serious and ordered a broader security review of the CPR system. Additional measures are already being introduced to prevent similar misuse.
The breach creates particular concerns about phishing and identity fraud because criminals could combine a person’s CPR number with their name and address to make scams appear more convincing. Danish authorities are warning people not to provide passwords or other confidential information simply because a caller or email sender already knows their personal details.
The incident has been reported to Denmark’s Data Protection Agency, while police are conducting a separate investigation. Authorities have not yet identified who was responsible or disclosed what the attackers intended to do with the information they accessed.