October 6, 2026 — Denmark is investigating a major data breach after unauthorized individuals accessed personal records belonging to approximately 8.8 million people through the country’s Central Person Register (CPR).
The incident exposed sensitive information including names, addresses, and CPR numbers, Denmark’s national personal identification numbers. The affected records include people currently living in Denmark, individuals who have moved abroad, and deceased people.
How the Breach Happened
According to Danish authorities, attackers did not directly break into the CPR system. Instead, they misused a private Danish company’s legitimate access to the registry.
The unauthorized activity took place for roughly 10 days in September. Authorities detected unusual activity on October 2 and subsequently determined the scale of the incident. The company's access to the registry has since been revoked.
Denmark’s Data Protection Agency reported a very large number of automated searches that appeared designed to identify valid CPR numbers, suggesting that the activity involved systematic data extraction.
Why the Breach Is Serious
The CPR system contains information on around 11 million registered individuals, meaning the incident potentially affected a large proportion of the database.
CPR numbers are particularly sensitive because they are used in areas such as healthcare, banking, and government services. The exposure could therefore create risks including identity fraud and targeted phishing attempts.
Authorities have not yet identified the individuals responsible or determined exactly how the company’s legitimate access was compromised.
Investigation Underway
Denmark’s police and data protection authorities are investigating the incident. Officials have also ordered a broader security review of the CPR system.
Authorities are advising people to be especially cautious about unexpected emails, text messages, or phone calls—even if the sender appears to know personal information such as their name, address, or CPR number.
The government has also extended the operating hours of its cyber-security hotline to help potentially affected individuals.
The incident highlights the growing security risks surrounding third-party access to highly sensitive government databases—and the importance of stronger monitoring and controls around legitimate credentials.
