Denmark population registry data breach affects 8.8 million people

by · BleepingComputer

Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals.

This includes people who live in the country, individuals who have moved abroad, and also deceased people.

The CPR is the country's national civil registry, containing personal information on residents, including names, addresses, dates of birth, marital status, and unique CPR identification numbers.

According to a CPR announcement published earlier today, threat actors misused a private Danish company's legitimate access to the registry system to obtain names, addresses, CPR numbers, and other information relating to registered members.

A separate announcement by the Danish Data Protection Agency says that the attack involved some form of brute-forcing to enumerate valid CPR numbers, and then extract the related data from each entry.

The CPR system currently holds data for 11 million registered citizens, so the incident impacted a large portion (80%) of that, but not everyone.

The security incident occurred in September 2026, but CPR administration became aware of the breach on October 2 and determined the size of the impact over the weekend.

The private company's access to the registry has now been blocked, and police have launched an investigation, which is currently underway.

"This is an extremely serious incident, which is why I have also informed Parliament’s Business and Digitalization Committee," stated Minister for Research, Education and Digitalization Christina Egelund.

"Together with all relevant authorities, we are working to establish the full extent of the incident."

Egelund said additional security measures have been implemented to prevent similar incidents on the CPR system, and urged citizens to stay on high alert for unsolicited communications.

A dedicated "cyber hotline" has been set up for potentially affected individuals,, and help and guidance are also available online at sikkerdigital.dk.

"In light of the incident, everyone is reminded never to disclose passwords or other confidential information in response to telephone calls, emails, or similar communications," the announcement warned.

"This also applies even if the recipient appears to know your name, address, and CPR number."

BleepingComputer has contacted the agency to learn more about the incident, including how the private company was compromised, but we have not received a response as of publication.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat