# Data on 8 Million People Stolen in Denmark’s Largest Recorded Government Breach

*Saturday, October 10, 2026 at 8:07 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-10-10T08:07:11.238Z (2h ago)
**Category**: cyber | **Region**: Europe
**Importance**: 9/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/20173.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers used a Danish company’s legitimate access to Denmark’s Central Person Register to steal names, addresses and ID numbers for about 8 million citizens and residents, in what officials say is the country’s biggest data breach so far.

A core Danish population database has been hit by a cyberattack that exposed the personal details of nearly everyone in the country, in what officials describe as Denmark’s largest data breach on record.

Hackers stole records on roughly 8 million citizens and residents from the Central Person Register, the system that underpins Denmark’s identity and civil-registration infrastructure. According to initial government statements, the attackers did not break directly into state servers. Instead, they misused a private Danish company’s lawful access to the register to siphon off names, addresses and national ID numbers.

The breach occurred in September but went undetected until 2 October. By the time it was discovered, the data had already been taken, leaving authorities to reconstruct what was accessed and how it might now be used.

Officials have not yet publicly attributed the attack or explained how the company’s credentials were compromised. The incident highlights a well-known but unresolved weakness: government data is only as secure as the contractors allowed to handle it.

For people in Denmark, the stolen fields are highly sensitive. Names, addresses and national ID numbers are the raw material for identity theft and financial fraud. Criminals can use them to open bank accounts, apply for loans, reroute mail or craft convincing phishing messages aimed at extracting more information. Even if no financial harm has yet been confirmed, the breach hands unknown actors the tools to impersonate millions of individuals for years.

The breach also strikes at public trust. Denmark has long promoted a centralized, digital model for delivering public services, built on confidence that the state can protect the information it holds. Learning that this infrastructure has been compromised via a commercial partner is likely to trigger calls to tighten how private companies access official databases.

Officials say there is no indication that core government systems were compromised beyond the misused access, and that the breach did not disrupt the operation of the register itself. From a security standpoint, however, the main damage has already occurred: personal data that cannot be revoked is now potentially in the hands of cybercriminals or foreign intelligence services.

The incident feeds into a wider European debate over how much citizen data should be centralized. Large registers make administration more efficient and support advanced digital services, but they also create attractive targets whose compromise can affect almost an entire population in one stroke.

Worldwide, the Danish case adds to a pattern of major attacks on identity, health and tax databases, sometimes by profit-motivated hackers and sometimes by states seeking detailed information on foreign citizens. Even if this breach turns out to be financially driven, the dataset can be sold and resold or combined with other leaks to build more detailed profiles.

A clear lesson emerges: outsourcing access does not outsource risk. When a contractor can pull full identity records, its internal controls effectively become part of the state’s security perimeter.

Key steps to watch now include whether Denmark introduces new technical and legal limits on how companies connect to the Central Person Register, whether citizens are offered new ID numbers or protective services, and whether investigators attribute the breach to a specific criminal group or foreign actor. Other European governments that maintain similar registers are likely to review their own contractor access paths in response.
