COPENHAGEN, DENMARK / RankWire.AI / – Authorities in Denmark are examining a significant security breach involving the country’s Central Person Register. Personal data related to approximately 8.8 million individuals was accessed without authorization. This exposed data included names, addresses, CPR numbers, and associated records. Officials stated that the attackers exploited a private Danish company’s legitimate access to search the CPR system. As a response, the CPR administration has suspended the company’s access while investigations continue to determine how the breach occurred.

The CPR administration identified suspicious activity on the evening of Oct. 2 after unusual search patterns were observed during September. Over the weekend, authorities analyzed the activity and verified the extent of the unauthorized access. The Central Person Register holds around 11 million records, covering current residents, individuals who have moved abroad, and deceased persons. Officials confirmed that the searches were confined to information categories that private companies are legally permitted to access via authorized CPR services.
The identity of those responsible for the activity remains unknown. Danish officials have not disclosed the private company whose authorized access was exploited by the attackers. The incident was reported to Datatilsynet, Denmark’s data protection authority, and police authorities are now conducting investigations with other relevant agencies. The government reported that its review showed no exposure of names and addresses protected under Denmark’s name and address protection scheme.
Data regulator assesses automated CPR system inquiries
Datatilsynet announced that it received the incident report from the CPR register on Oct. 4. The authority explained that the breach involved a very high volume of automated searches against the CPR system. These searches aimed to verify the validity of CPR numbers, according to the notification. The regulator is now investigating the circumstances of the breach, how access was gained, and who bears responsibility for processing the involved personal data. Further information will be shared once enough details are available, the agency added.
Research, Education and Digitalisation Minister Christina Egelund described the incident as highly serious and briefed parliament’s Business and Digital Affairs Committee. Additionally, she mandated a comprehensive security review of the CPR system. The Danish government has implemented measures to prevent similar incidents, while the CPR administration continues to trace the sequence of events. Authorities emphasized that the investigation is still in its early stages and that technical analyses may clarify further details.
Public advised to remain vigilant against fraud
Danish authorities urged residents to be cautious of potential fraud attempts via phone calls, emails, or other messages that might utilize exposed personal data. Officials advised people never to share passwords or other confidential information just because a caller or message sender knows their name, address, or CPR number. The government recommended consulting official digital security resources and Denmark’s cyber hotline. This warning came after confirmation that the breach involved data belonging to millions of individuals registered in the national population system.
Authorities continue to investigate the breach method, affected records, and safeguards surrounding private-company access to the CPR system. Additionally, Datatilsynet is separately examining the data protection issues stemming from the incident. The CPR administration has cut off the company’s access and initiated security measures, while broader efforts are underway to review the entire registry. As of Oct. 7, officials have not publicly identified the perpetrators, disclosed the private company involved, or confirmed the precise technique used to abuse its authorized access.
