Published: · Region: Global · Category: cyber

Denmark Probes Breach That Exposed CPR Numbers for About 8.8 Million People

Unauthorized parties used a private company’s lawful access to Denmark’s national register to pull names, addresses, and CPR numbers for about 8.8 million people over 10 days, prompting a police investigation.

Denmark is investigating a major data breach after authorities disclosed that unauthorized parties accessed personal information for about 8.8 million people via the country’s central population register.

Officials say the data retrieved includes names, addresses, and CPR numbers, the personal identification codes used across Danish public and private services. According to initial estimates, roughly four in five records in the national register were queried in automated lookups that ran over 10 days before being detected and shut down. Police are investigating.

The incident did not involve a direct intrusion into government servers. Instead, attackers abused a private company’s legitimate access to the register, using valid digital credentials to run large volumes of queries. That points to weaknesses in how trusted third parties connect to Denmark’s identity systems rather than a failure of the core database itself.

For residents, the exposure of CPR numbers alongside names and addresses creates long‑term risks. CPR numbers are widely used in tax, health, banking, and other services and are not easy to change. Having that combination of details in unknown hands can simplify identity‑theft attempts and fraud schemes.

Because Denmark’s central register feeds information to many public and private systems, this breach also tests a broader model of digital government in which a single national database underpins online services. The attackers’ use of a private company’s access highlights how much that model depends on the security of every connected partner.

Authorities have not publicly identified who carried out the queries or what they intend to do with the data. There has been no official word on whether the information has already been copied, sold, or otherwise misused.

Next steps will center on tracing the source of the automated lookups, assessing how much data was actually exfiltrated, and deciding what protections to offer affected residents. The government will also face choices about tightening or redesigning private‑sector access to the register, while other countries running similar centralized identity databases are likely to re‑examine their own third‑party connections in light of Denmark’s experience.

Sources