COPENHAGEN, DENMARK / RankWire.AI / – Danish authorities are currently probing a significant security breach involving the country’s Central Person Register. Unauthorized individuals gained access to personal information of approximately 8.8 million people. The compromised data included names, addresses, CPR numbers, and related records. Officials indicated that the attackers exploited lawful access granted to a private Danish company to search the CPR system. The CPR administration has suspended the company’s access while investigations determine how the breach occurred.

The CPR administration identified suspicious activity on the evening of Oct. 2, after observing unusual searches during September. Over the weekend, authorities reviewed these activities and confirmed the extent of the unauthorized access. Denmark’s Central Person Register holds roughly 11 million records, covering current residents, those who have moved abroad, and deceased individuals. Officials emphasized that the searches remained within the categories of data that private companies can legally access through authorized CPR services.
The identity of those responsible for the activity remains unknown. Danish authorities have not disclosed the private company whose lawful access was exploited by the attackers. The CPR administration reported the incident to Datatilsynet, Denmark’s data protection authority, and police are conducting investigations alongside other relevant agencies. The government stated that its review found no exposure of names and addresses belonging to individuals protected under Denmark’s name and address concealment scheme.
Regulator investigates automated searches within CPR system
Datatilsynet announced it received the incident report from the CPR register on Oct. 4. The authority explained that the case involves a very high volume of automated queries targeting the CPR system. These searches aimed to verify valid CPR numbers, according to the notification. Datatilsynet is examining the circumstances of the breach, how access was enabled, and who holds responsibility for processing the personal data involved. The regulator indicated it will share more details once sufficient information is available.
Research, Education and Digitalisation Minister Christina Egelund called the incident highly serious and briefed Denmark’s Business and Digital Affairs Committee. She also mandated a comprehensive security review of the CPR system. The government has initiated measures to prevent similar breaches in the future, while the CPR administration continues to trace the sequence of events. Officials noted that the investigation is still in its early stages and that technical assessments might clarify some details further.
Authorities alert public to potential fraud threats following breach
Danish authorities advised residents to stay vigilant against scam calls, emails, and messages that might leverage exposed personal data. Officials warned that individuals should never share passwords or other sensitive information just because a caller or sender appears to know their name, address, or CPR number. The government recommended consulting official digital security guidelines and contacting Denmark’s cyber hotline. This warning followed confirmation that the unauthorized activity involved data belonging to millions of registered individuals in the national population system.
Authorities continue to examine how access was obtained, which records were affected, and the safeguards governing private-sector use of the CPR system. Datatilsynet is also independently reviewing the data protection issues raised by the incident. The CPR administration has revoked the company’s access and initiated security measures. Meanwhile, officials are conducting a broader review of the registry. As of Oct. 7, authorities had not publicly identified the attackers, disclosed the private company’s name, or confirmed the specific method used to exploit the authorized access.
