8.8 Million Danish Identity Records Exposed After Attackers Abuse Trusted Company Access
Denmark Orders Security Review After Millions Of CPR Records Are Accessed
Unauthorised users obtained names, addresses and national identification numbers after exploiting a private company’s legitimate access to Denmark’s Central Person Register.
Denmark is investigating a huge security incident after unauthorised users gained access to personal information linked to about 8.8 million people in the country’s Central Person Register, known as the CPR.
The figure is larger than Denmark’s current population because the register contains historical records as well as information on people currently living in the country. It includes people who have moved abroad and those who have died.
The information accessed includes names, addresses and CPR numbers, the unique personal identification numbers used across Danish public services and much of the private sector.
What makes the incident particularly significant is how the data appears to have been reached.
Authorities say the attackers exploited a private Danish company’s legitimate access to the CPR system. Rather than simply forcing their way through the central database itself, the unauthorised users appear to have operated through a route that was already trusted.
That makes the trusted connection itself central to the investigation.
How 8.8 Million Records Became Accessible
Denmark’s CPR system sits at the heart of the country’s administrative infrastructure.
Every person registered in the system receives a unique CPR number. The identifier is used across government, healthcare, finance and other services where an individual needs to be reliably matched with a record.
The register contains information on roughly 11 million people in total. About 8.8 million of those records were affected by the unauthorised access.
Authorities have not publicly identified the private company whose access was misused.
They have also not established publicly who was behind the activity or exactly how the attackers gained control of the company’s access.
Private organisations can lawfully receive access to specific CPR information when they have a legitimate reason to retrieve it.
In this case, that authorised route appears to have become the weakness.
It illustrates an important problem in modern cybersecurity. Attackers do not always have to defeat the most heavily protected part of a network if they can instead compromise a trusted user, contractor or connected organisation.
A similar danger emerged when France’s tax system was targeted in a breach affecting hundreds of thousands of people and businesses.
The Suspicious Activity Continued For Days
The administration responsible for Denmark’s CPR system became aware of unusual activity on the evening of 2 October 2026.
Investigators subsequently established that unauthorised access had taken place during September.
Denmark’s digitalisation minister, Christina Egelund, said the misuse had continued for around ten days and acknowledged that the security surrounding the company’s access had not been strong enough.
That creates another important question for investigators.
A system containing some of the country’s most sensitive identity information was being queried on an extraordinary scale, yet the activity was not stopped immediately.
The company’s access has since been disabled.
Authorities are working with specialists to establish exactly what happened, while police are investigating the incident. Denmark’s data protection regulator has also been notified.
Egelund has ordered a wider examination of security surrounding the CPR system, with additional measures intended to prevent a similar incident.
What Information Was Accessed?
The confirmed information includes names, addresses and CPR numbers.
A CPR number is one of the most important identifiers attached to a person in Denmark. It is widely used when public authorities and private organisations need to establish or verify an individual’s identity.
People who had registered for name and address protection were not included in the unauthorised disclosure of those protected name and address details, according to the initial assessment.
There is also an important distinction between obtaining identity information and directly taking control of somebody’s accounts.
The exposed CPR records do not automatically provide criminals with a victim’s bank password, email password or MitID authentication credentials.
But the information can still be extremely valuable.
Someone who already knows a target’s real name, address and CPR number has a much stronger foundation for impersonation and social engineering than a criminal sending random phishing messages.
That means the greatest threat may not come from the original database access itself.
It may come from what somebody attempts to do with the information afterwards.
Why The Fraud Risk Could Continue
Identity information presents a different security problem from a stolen password.
Passwords can be changed.
A person’s name, personal history and national identification number can remain associated with them for years.
That gives stolen identity information potential value long after the original security breach has been contained.
Criminals could use genuine personal details to make fraudulent communications appear more convincing.
A caller pretending to represent a bank or public authority, for example, could quote information that makes the conversation appear legitimate before attempting to obtain passwords, payment details or access credentials.
Danish authorities have warned people not to disclose passwords or other confidential information simply because somebody contacting them already knows their name, address or CPR number.
That distinction is critical.
Possessing accurate personal information does not prove that the person contacting you is legitimate.
The same pattern appears throughout modern cyberattacks involving stolen identities, credentials and trusted access.
The first breach obtains information. The next stage can involve using that information to manipulate a person into giving up something even more valuable.
The Weak Point Was Trust
The most important security lesson may be that the central CPR database did not have to be broken open in the way people traditionally imagine a government database being hacked.
The route identified by Danish authorities involved a company that was already permitted to query the system.
Modern government infrastructure depends on thousands of these relationships.
Departments, contractors, employers, banks and other organisations can require access to information held inside central systems.
Those connections make digital services possible.
They also create additional points where security has to work.
If a trusted organisation, account or credential is compromised, an attacker may be able to operate through an access route that the central system has been designed to accept.
The problem is not unique to Denmark.
Questions around access pathways, credentials and connected systems have also featured in other public-sector incidents, including the cyberattack involving the UK Foreign Office.
For Danish investigators, the next task is not simply establishing that the data was accessed.
They need to determine how control of the company’s access was obtained, why the abnormal activity continued for days and whether any information beyond the categories currently confirmed was reached.
Why 8.8 Million Is Higher Than Denmark’s Population
The scale of the incident initially creates an apparent contradiction.
Denmark has a population of just over six million people, yet approximately 8.8 million records were accessed.
The explanation lies in how the CPR database works.
It is not merely a list of everyone currently living in Denmark.
The system contains approximately 11 million registered people in total, including current residents, people who previously lived in the country and later moved abroad, and people who have died.
The 8.8 million figure therefore refers to registered individuals whose information was accessed. It does not mean that 8.8 million people currently living in Denmark were affected.
Even with that qualification, the scale remains enormous.
The affected records represent roughly four-fifths of the people registered in the CPR system.
Major Questions Remain Unanswered
Several important details have not yet been made public.
The company whose legitimate access was abused has not been named.
The identity or location of the attackers has not been established publicly.
It is also unclear exactly how the attackers obtained access to the company’s systems or credentials.
Another major unknown is what happened to the information after it was retrieved.
There has been no public confirmation that the dataset has been sold, published or used in subsequent fraud attempts.
Those questions will determine how the incident develops.
A large privacy breach is serious in itself. A copied dataset moving into criminal markets or being used for targeted impersonation could create consequences long after the original access point has been closed.
Investigators will also need to understand why the scale and pattern of searches did not trigger an earlier response.
Egelund has already acknowledged shortcomings in the security arrangements.
The longer-term test will be whether Denmark can introduce controls capable of recognising abnormal behaviour even when requests appear to come through an organisation that has legitimate permission to use the system.
The Breach Is Over. The Risk May Not Be.
The compromised access route has been shut down, but stolen information cannot necessarily be recovered.
Once personal data has been copied, the organisation that originally held it loses control over every potential copy.
Denmark can investigate the intrusion, strengthen its systems and tighten the rules surrounding access to the CPR database.
What it cannot do is make duplicated identity information disappear if the attackers retained it.
For affected people, the most noticeable consequence could therefore arrive weeks or months after the original breach.
It could be a phone call, email or message that appears unusually credible because the person behind it already knows information that would normally help establish trust.
The breach began through a trusted route into Denmark’s identity infrastructure.
The lasting security challenge will be ensuring that the information taken through that route cannot be used to manufacture trust somewhere else.
Sources
Forsknings-, Uddannelses- og Digitaliseringsministeriet — Omfattende uautoriseret adgang til borgeres CPR-oplysninger — Confirms the approximately 8.8 million affected records, categories of information accessed, misuse of company access and official response.
Datatilsynet — Datatilsynet er opmærksom på sag om opslag i CPR — Confirms that Denmark’s data protection regulator received notification of the incident and is examining the large volume of CPR lookups.
BleepingComputer — Denmark Population Registry Data Breach Affects 8.8 Million People — Provides additional chronology and context on the incident and the scale of the affected registry.
Next Reads
France’s Tax System Hacked As Data On 678,000 People And Businesses Is Stolen — Another major European government data incident involving compromised access and sensitive personal information.
Cyber Attacks Explained: How Hackers Profit And States Fight — Explains how attackers gain access, exploit credentials and turn stolen information into fraud, extortion or strategic leverage.
UK Foreign Office Cyberattack Confirmed: What’s Known, What’s Still Unclear, And Why It Matters Now — Looks at another government cyber incident where the access route and data potentially exposed became central questions.