COPENHAGEN, DENMARK / RankWire.AI / – Authorities in Denmark are looking into a significant breach involving the nation’s Central Person Register. Unauthorized individuals gained access to personal information linked to approximately 8.8 million individuals. The compromised data comprised names, addresses, CPR numbers, and related records. Officials stated that the attackers exploited a lawful connection maintained by a private Danish firm to access the CPR system. The CPR administration has since suspended the company’s access as investigations into the incident continue.

The CPR administration identified suspicious activity on the evening of Oct. 2, after observing unusual search patterns during September. Over the weekend, officials reviewed the activity and verified the extent of the unauthorized data access. The Central Person Register holds around 11 million records, including details of current residents, individuals who have moved abroad, and deceased persons. Authorities confirmed that the searches were confined to information categories that private companies are permitted to access through authorized CPR services.
No suspects have been identified yet, and Danish officials have not disclosed the name of the private firm whose lawful access was exploited by the attackers. The CPR administration reported the breach to Datatilsynet, Denmark’s data protection authority, while police and relevant agencies are also conducting investigations. The government assured that its review found no exposure of names and addresses covered under Denmark’s name and address protection scheme.
Regulatory body reviews automated CPR inquiries
Datatilsynet announced it received the incident report from the CPR register on Oct. 4. The authority explained that the case involved a very high volume of automated searches against the CPR database. These searches aimed to verify valid CPR numbers, according to the notification. Datatilsynet is examining the circumstances, how the unauthorized access was enabled, and who is responsible for the processing of personal data involved. The agency stated it will provide additional information once there is a clear basis to do so.
Research, Education and Digitalisation Minister Christina Egelund described the incident as deeply serious and briefed Denmark’s parliament’s Business and Digital Affairs Committee. She also mandated a comprehensive security review of the CPR system. The government has implemented measures aimed at preventing similar breaches, while the CPR administration continues to map the sequence of events. Officials noted that the investigation remains in early stages and that the technical review may clarify details further.
Public warned about potential fraud schemes
Danish authorities have urged residents to stay vigilant against scams involving fraudulent calls, emails, and messages that might utilize exposed personal data. Officials advised that individuals should never disclose passwords or other sensitive information just because someone knows their name, address, or CPR number. The government recommended consulting official digital security guidance and Denmark’s cyber hotline. This warning follows confirmation that the breach involved data belonging to millions of people registered in the national population system.
Authorities continue to analyze the method of access, the scope of affected records, and the safeguards around private sector use of the CPR system. Datatilsynet is separately reviewing data protection issues raised by the incident. The CPR administration has disconnected the company’s access and initiated security protocols, while officials are conducting a broader review of the registry. As of Oct. 7, authorities had not publicly identified the perpetrators, revealed the company’s name, or confirmed the exact means by which the authorized access was misused.
