Denmark Probes Breach of 8.8 Million CPR Records After Misuse of Private Firm’s Register Access
Denmark says unauthorized parties used a private company’s lawful connection to the national register to pull names, addresses, and CPR numbers tied to about 8.8 million people over 10 days, exposing roughly four in five records in the country’s core population database.
A core pillar of Denmark’s digital state has suffered a major breach, with personal data on millions of people exposed through a trusted access point.
Authorities say unauthorized parties accessed names, addresses and CPR numbers for about 8.8 million people via a private company’s lawful access to the national register. Automated lookups ran for 10 days before the activity was detected, according to the official account.
The figure amounts to roughly four in five records in Denmark’s central population register. In a country of around six million residents, that scale suggests the incident likely covers current residents and other entries held in the system.
The CPR number is the personal identification code used across Danish public and private services. Tied together with names and addresses, it can be a powerful tool for anyone attempting identity theft, fraudulent financial activity, or targeted social‑engineering scams.
Police have opened an investigation, but officials have not yet disclosed who carried out the automated queries or what they intend to do with the harvested data. They have also not detailed the exact technical method used beyond confirming that the attackers went through a company that already had legitimate access to the register.
The incident highlights the risks around third‑party connections to sensitive state databases. Instead of breaching the national register directly, the intruders appear to have abused a trusted link, raising questions about how such links are monitored and how quickly unusual query patterns are flagged.
For Danish citizens, banks, and government agencies, the breach means that a large volume of core identity information should now be treated as exposed. That in turn may force service providers to rethink how they authenticate users when CPR data and basic personal details can no longer be assumed to be secret.
Key decisions to watch in the coming weeks include whether Denmark moves to add extra security layers on top of CPR‑based identification, whether there is any plan to reissue identifiers in particularly high‑risk cases, and what police learn about how the data is being used or traded.
Sources
- OSINT