COPENHAGEN, DENMARK / RankWire.AI / – Danish authorities are investigating a major breach of the country’s Central Person Register. Unauthorized parties accessed personal data tied to about 8.8 million people. The exposed information included names, addresses, CPR numbers and related records. Officials said the attackers used a private Danish company’s lawful access to search the CPR system. The CPR administration has stopped the company’s access while authorities examine how the incident occurred.

The CPR administration detected irregular activity on the evening of Oct. 2 after unusual searches took place during September. Authorities reviewed the activity over the weekend and confirmed the scale of the unauthorized access. Denmark’s Central Person Register contains about 11 million records, including current residents, people who moved abroad and deceased individuals. Officials said the searches stayed within the categories of information that private companies can legally access through authorized CPR services.
The investigation has not identified who carried out the activity. Danish officials also have not named the private company whose lawful access the attackers used. The CPR administration reported the incident to Datatilsynet, Denmark’s data protection regulator, and police are investigating with other relevant authorities. The government said its review found no exposure of names and addresses belonging to people registered under Denmark’s name and address protection scheme.
Regulator examines automated CPR searches
Datatilsynet said it received the incident report from the CPR register on Oct. 4. The regulator said the case involved a very large number of automated searches against the CPR system. Those searches aimed to identify valid CPR numbers, according to the notification. Datatilsynet is examining what happened, how the access became possible and who bears responsibility for processing the personal data involved. The regulator said it would provide further information when there is a sufficient basis to do so.
Research, Education and Digitalisation Minister Christina Egelund called the incident deeply serious and informed parliament’s Business and Digital Affairs Committee. She also ordered a broad security review of the CPR system. The government has started measures intended to prevent similar incidents, while the CPR administration continues mapping the sequence of events. Authorities said the investigation remains at an early stage and that the technical review could refine confirmed details.
Authorities warn public about fraud risks
Danish authorities urged residents to remain alert for fraudulent calls, emails and other messages that may use exposed personal details. Officials said people should never provide passwords or other confidential information simply because a caller or sender knows their name, address or CPR number. The government directed residents to official digital security guidance and Denmark’s cyber hotline. The warning followed confirmation that the unauthorized activity involved data belonging to millions of registered people in the national population system.
Authorities continue to assess the access route, affected records and safeguards around private-company use of the CPR system. Datatilsynet is separately reviewing the data protection issues raised by the incident. The CPR administration has cut off the company’s access and launched security measures, while officials conduct a wider review of the registry. As of Oct. 7, authorities had not publicly identified the attackers, disclosed the company’s name or confirmed the exact method used to misuse its authorized access.
