Denmark’s Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals.
This includes people who live in the country, individuals who have moved abroad, and also deceased people.
The CPR is the country’s national civil registry, containing personal information on residents, including names, addresses, dates of birth, marital status, and unique CPR identification numbers.
According to a CPR announcement published earlier today, threat actors misused a private Danish company’s legitimate access to the registry system to obtain names, addresses, CPR numbers, and other information relating to registered members.
A separate announcement by the Danish Data Protection Agency says that the attack involved some form of brute-forcing to enumerate valid CPR numbers, and then extract the related data from each entry.
The CPR system currently holds data for 11 million registered citizens, so the incident impacted a large portion (80%) of that, but not everyone.
The security incident occurred in September 2026, but CPR administration became aware of the breach on October 2 and determined the size of the impact over the weekend.
The private company’s access to the registry has now been blocked, and police have launched an investigation, which is currently underway.
“This is an extremely serious incident, which is why I have also informed Parliament’s Business and Digitalization Committee,” stated Minister for Research, Education and Digitalization Christina Egelund.
“Together with all relevant authorities, we are working to establish the full extent of the incident.”
Egelund said additional security measures have been implemented to prevent similar incidents on the CPR system, and urged citizens to stay on high alert for unsolicited communications.
A dedicated “cyber hotline” has been set up for potentially affected individuals,, and help and guidance are also available online at sikkerdigital.dk.
“In light of the incident, everyone is reminded never to disclose passwords or other confidential information in response to telephone calls, emails, or similar communications,” the announcement warned.
“This also applies even if the recipient appears to know your name, address, and CPR number.”
BleepingComputer has contacted the agency to learn more about the incident, including how the private company was compromised, but we have not received a response as of publication.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
OpenAI hacked Australian Medicare govt site, probed data providers
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records
Berlin confirms data theft after Rhysida ransomware attack claims
Sakura Internet hack exposes data of up to 1.36 million accounts
Anthropic asks Claude users to share voice data for AI model training
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
Citrix patches NetScaler SAML zero-day exploited in attacks
Overdue a password health-check? Audit your Active Directory for free
Your access review passed cleanly, but it never saw the agents swimming under the surface. See how Token Security fishes out every one of them.
73% of orgs feel prepared for attacks. 82% had a browser incident last year anyway.
Free Identity Governance for up to 150 Users: Try Our Community Edition
Free Identity Governance for up to 150 Users: Try Our Community Edition
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


