COPENHAGEN, DENMARK / RankWire.AI / – Danish authorities are probing a significant breach involving the country’s Central Person Register. Unauthorized individuals gained access to personal data of approximately 8.8 million people. The compromised information included names, addresses, CPR numbers, and related records. Officials stated that the attackers exploited lawful access granted to a private Danish company to search the CPR system. The CPR administration has suspended the company’s access as authorities investigate how the breach occurred.

The CPR administration identified suspicious activity on the evening of Oct. 2 after unusual searches had taken place during September. Over the weekend, authorities reviewed the logs and confirmed the extent of the unauthorized access. Denmark’s Central Person Register holds about 11 million records, covering current residents, people who moved abroad, and the deceased. Officials emphasized that the searches remained within the categories of information that private companies can legally access through authorized CPR services.
No suspects have been identified in connection with the activity. Danish officials have also not disclosed which private company’s lawful access was exploited. The CPR administration reported the breach to Datatilsynet, Denmark’s data protection authority, and police are conducting an investigation with other relevant agencies. The government stated that its review revealed no exposure of names and addresses protected under Denmark’s name and address protection scheme.
Regulator probes automated searches within CPR system
Datatilsynet reported receiving the incident notification from the CPR register on Oct. 4. The regulator noted that the case involved a very large number of automated searches targeting the CPR system. These searches aimed to verify valid CPR numbers, according to the report. Datatilsynet is examining what happened, how the access was gained, and who is responsible for handling the personal data. The authority said it will provide more details once there is enough information to do so.
Research, Education and Digitalisation Minister Christina Egelund described the incident as deeply serious. She briefed Denmark’s Business and Digital Affairs Committee. She also ordered a comprehensive security review of the CPR system. The government has initiated steps to prevent similar incidents in the future. Meanwhile, the CPR administration continues to analyze the sequence of events. Authorities indicated that the investigation is still in its early stages. The technical review may clarify some confirmed details.
Officials alert the public about potential fraud risks
Danish authorities advised residents to stay vigilant against fraud attempts via phone calls, emails, and other messages that might use the exposed personal data. Officials stressed that individuals should never share passwords or confidential information just because a caller or sender knows their name, address, or CPR number. The government directed residents to official digital security resources and Denmark’s cyber hotline. The warning came after confirmation that the breach involved data belonging to millions of registered people in the national population database.
Authorities continue to assess how the hackers accessed the data, which records were affected, and the safeguards around private-company use of the CPR system. Separately, Datatilsynet is reviewing the data protection implications of the breach. The CPR administration has cut off the private company’s access and implemented security measures. Officials are also conducting a broader review of the register. As of Oct. 7, authorities had not publicly identified the perpetrators, disclosed the company’s name, or confirmed the method used to misuse authorized access.
