8.8 Million Records Exposed in Major Denmark Data Breach
Denmark is investigating a major breach in which unauthorised users accessed names, addresses and personal identification numbers linked to about 8.8 million people.

Denmark has confirmed a major security breach involving its Central Person Register, known as the CPR, after unauthorized individuals gained access to personal information associated with approximately 8.8 million registered people.
The Danish Ministry of Research, Education and Digitalization said Monday that the compromised information includes names, addresses and CPR numbers, the country's personal identification numbers. The incident affects far more records than Denmark's roughly six million current residents because the CPR also contains information on people who have emigrated and those who have died.
Authorities said the attackers did not break directly into the CPR's core system in the conventional sense. Instead, they appear to have abused the legitimate access granted to a private Danish company, using that access to conduct searches and retrieve information from the register. The company has not been publicly identified.
The CPR administration said it detected unusual activity on Friday, October 2, after abnormal behaviour had occurred during September. By the weekend, authorities had determined that unauthorized parties had obtained information on millions of registered individuals. The company's access to the register has since been stopped.
The Danish Data Protection Agency, Datatilsynet, said it received a formal notification of the incident on Sunday. It said the case involved a very large number of automated searches apparently designed to identify valid CPR numbers and that it was investigating what happened, how it happened and who was responsible for processing the personal information.
Digitalization Minister Christina Egelund described the incident as extremely serious and acknowledged that the security arrangements surrounding the private company's access were inadequate. She said warning mechanisms should have detected the suspicious activity sooner, given that the unusual searches continued for several days.
The authorities have not disclosed who carried out the unauthorized searches, how the company's access was compromised or whether investigators believe the perpetrators had a specific criminal or financial motive. Those questions remain part of the ongoing investigation.
Not everyone in the CPR system was affected in the same way. Danish authorities said names and addresses belonging to people who had registered for protected name-and-address status were not included in the unauthorized access.
The scale of the incident is nevertheless significant. The CPR contains information on about 11 million registered people, including current residents, former residents and deceased individuals. The 8.8 million figure therefore represents a substantial portion of the information held in the national system, rather than 8.8 million people currently living in Denmark.
Cybersecurity experts have warned that the combination of names, addresses, birth information and personal identification numbers could make social-engineering and phishing attacks more convincing. Aarhus University cybersecurity professor Jens Myrup Pedersen said criminals could potentially combine the information with other publicly available material to make fraudulent messages appear to come from government agencies or other trusted organizations.
Authorities are consequently warning members of the public to be especially cautious about unexpected calls, emails or text messages. The government has stressed that people should not provide passwords or other confidential information simply because a caller appears to know their name, address or CPR number.
The breach is particularly sensitive because the CPR is a foundational part of Denmark's highly digitalized public administration. Personal identification numbers are used across a wide range of interactions with government agencies and private organizations, making the protection of the system important not only for privacy but also for public trust in digital services.
Denmark has launched a broader security review while police and data-protection authorities investigate the incident. A national digital-security hotline has also extended its opening hours to provide guidance to people concerned about possible misuse of their information.
The episode highlights a growing cybersecurity problem that extends beyond traditional hacking of government servers: legitimate access can itself become a vulnerability when credentials, accounts or trusted third-party systems are abused. Denmark's experience shows how a single compromised access route can potentially expose information on millions of people even when the underlying government database remains operational.
For a country widely regarded as one of Europe's most digitally advanced societies, the incident is therefore more than a large data leak. It is a test of whether the safeguards surrounding interconnected public databases can keep pace with increasingly automated and sophisticated attempts to exploit trusted access. The investigation will now have to establish not only who obtained the information, but why existing controls failed to detect the activity sooner and what changes are needed to prevent a similar breach from affecting millions more records.
More on Technology

Technology
Google’s Gemini Linked to First Known AI ‘Breakout’ During Cybersecurity Test
19 Sept 2026
Technology
Hackers Drain $320 Million in Bitcoin From Liquid Network Wallet
7 Sept 2026

Technology
Google Picks 15 South African Startups for 2026 AI Accelerator
5 Oct 2026

Technology
Trump, AI CEOs Sign Voluntary Safety Pact as Pressure Grows Over Advanced AI Risks
30 Sept 2026

Technology
SpaceX’s Starship Reaches Orbit for First Time in Historic Test Flight
29 Sept 2026
You may also like
Technology
Starlink Ground Station Fire Sparks Sabotage Probe in Poland
25 Sept 2026

Technology
UK Watchdog Moves to Give AI Assistants More Search Options Beyond Google
24 Sept 2026

Technology
Singapore National Pleads Guilty to $245m Bitcoin Heist in US
11 Sept 2026

Technology
Starbase Technologies Puts Emerging African Creators in the Spotlight with Yolly
3 Oct 2026

Technology
Meta Stock Enjoys Best Month Since 2022 on AI Momentum
1 Oct 2026

Technology
Anthropic Faces Fresh Setback as US Court Upholds Pentagon Blacklist
28 Sept 2026