Data breach at Denmark’s national population register exposes 8.8 million people
Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.
Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register, the government said Monday.
The perpetrators exploited an unnamed domestic company’s legitimate access to Denmark’s Central Person Register (CPR) to compromise names, addresses and CPR numbers — roughly comparable to Social Security numbers in the U.S.
In total, the register holds information on around 11 million people, including current residents, people who have moved abroad and those who are deceased. Denmark’s current population is just over six million.
“This is a deeply serious incident,” Christina Egelund, the minister for research, education and digitalisation, said in a statement. She added that she had ordered a broad security review of the system, and that the country’s hotline for digital security will be operating at extended hours, from 8 a.m. to midnight, in the coming days.
Officials said they first detected irregular activity affecting the CPR system on Friday. Investigations over the weekend determined that the breach occurred during September, they said, although they did not comment on who the perpetrators may be.
Denmark’s Data Protection Agency said it was notified of the breach Sunday and described it as involving a very large number of automated searches on the system aimed at identifying valid CPR numbers.
The 10-digit numbers, which begin with a person’s date of birth, are used for healthcare, banking and government services in Denmark. As CPR numbers are meant to last a lifetime, there are fears the risks to those impacted could have a very long tail.
Similar population-scale breaches of national registries have been reported in Argentina in 2021, Turkey in 2016, India in 2018, Israel in 2006, and elsewhere.
“This incident demonstrates the inherent risk of highly centralized national databases when private companies are granted direct access to sensitive records,” said Dray Agha, senior manager of security operations at cybersecurity company Huntress.
“A compromised account at a single supplier can bypass an organisation’s core security controls and turn a legitimate connection into a massive data exposure.”
Nathan Davies-Webb, a principal consultant at security engineering firm Acumen Cyber, said: “Centralised systems like this should be treated with the utmost importance.”
“Overall, it is very positive to see the current transparency, especially the extended hours on the digital security hotline,” he said. “These behaviours can indicate that response plans are in place and being followed.”
The incident is the most significant to affect the CPR system since 2015, when two unencrypted CDs containing CPR information on more than five million people were mistakenly delivered to the Chinese Visa Application Centre in Copenhagen. At the time, authorities said there was no evidence the data had been copied or leaked.

Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79