COPENHAGEN, DENMARK / RankWire.AI / – Authorities in Denmark are investigating a breach involving unauthorized access to personal data within the nation’s Central Person Register, known as CPR. The incident impacted records associated with approximately 8.8 million individuals, including names, addresses, CPR identification numbers, and other registered details. Officials confirmed that the attackers used credentials linked to a private Danish company with legitimate permission to search the national population database, though the company’s name has not been disclosed.

The CPR administration detected unusual activity on the evening of Oct. 2 following a series of searches conducted during September. Over the subsequent weekend, officials analyzed the activity to determine the scope of the breach. Denmark’s CPR database holds around 11 million records, encompassing current residents, those who have moved abroad, and deceased persons. Authorities emphasized that the searches stayed within the categories of information accessible through authorized CPR services.
Those responsible for the unauthorized searches have not yet been identified. The CPR administration revoked the company’s access once suspicious activity was discovered. Danish police and relevant authorities are investigating how the breach happened and which records the searches accessed. Officials also checked whether any protected names and addresses under Denmark’s name and address protection scheme were involved; they confirmed that such protected information was not part of the exposed data.
Data authority investigates automated CPR inquiries
Datatilsynet, Denmark’s data protection agency, received the incident report on Oct. 4. The agency stated that a very high volume of automated searches had targeted the CPR system. The notification indicated these searches aimed to verify valid CPR numbers. Datatilsynet is now examining how unauthorized parties gained access and what personal information was obtained, along with assessing responsibility for processing the compromised data under Danish data protection laws.
Research, Education and Digitalisation Minister Christina Egelund described the breach as highly serious and briefed Denmark’s parliament’s Business and Digital Affairs Committee. She mandated a comprehensive security review of the CPR system and its access controls. The government has initiated measures to reduce the risk of similar incidents in the future. Authorities are continuing to trace the sequence of events and scrutinize safeguards employed by private organizations with authorized access to CPR information.
Public cautioned on potential scam risks
Officials in Denmark have urged citizens to remain vigilant against fraudulent calls, emails, and messages that might contain exposed personal details. They warned residents not to share passwords or confidential information if someone contacts them claiming to already know their name, address, or CPR number. The government has directed the public to official digital security resources and Denmark’s cyber hotline. Authorities have not confirmed that the accessed data was used for fraud, identity theft, or other criminal activities beyond the unauthorized searches.
Investigations into the breach continue, focusing on the access route, the records affected, and the security measures protecting private use of the CPR system. The identity of the company involved and the specific method of misuse remain undisclosed. Authorities have not publicly identified those responsible for the searches. As of Oct. 7, the CPR administration, police, and regulators are conducting separate reviews while Denmark assesses security protocols surrounding its national population register.
