COPENHAGEN, DENMARK / RankWire.AI / – Danish authorities are examining a significant breach involving the country’s Central Person Register. Personal data for approximately 8.8 million individuals was accessed without authorization. The compromised information comprised names, addresses, CPR numbers, and related records. Officials stated that the attackers exploited a private Danish company’s lawful access to search the CPR system. The CPR administration has temporarily revoked this company’s access while investigations determine how the breach occurred.

The CPR administration detected suspicious activity on the evening of Oct. 2, following unusual search patterns observed during September. Over the weekend, authorities reviewed the incident and confirmed the extent of the unauthorized access. The Central Person Register holds around 11 million records, including current residents, individuals who have moved abroad, and deceased persons. Officials emphasized that the searches were confined to information categories that private companies are legally permitted to access via authorized CPR services.
To date, the perpetrators of the activity have not been identified. Danish officials have not disclosed the private company whose legitimate access was exploited. The CPR administration reported the breach to Datatilsynet, Denmark’s data protection authority, and police are investigating alongside other relevant agencies. The government stated that its review found no evidence of names and addresses belonging to individuals protected under Denmark’s name and address protection scheme being exposed.
Regulator looks into automated CPR search activities
Datatilsynet confirmed it received the incident report from the CPR register on Oct. 4. According to the notification, the case involved a very high volume of automated searches performed against the CPR system. These searches aimed to verify valid CPR numbers. The regulator is now examining the circumstances that made such access possible, who is responsible, and what personal data was processed. Further information will be shared once sufficient details are available, the authority added.
Research, Education and Digitalisation Minister Christina Egelund described the incident as profoundly serious and briefed Denmark’s Business and Digital Affairs Committee. She also ordered a comprehensive security review of the CPR system. The government has initiated measures to prevent similar breaches, while the CPR administration continues to trace the sequence of events. Authorities noted that the investigation is still in its early stages, and the technical review may provide more precise details later.
Public advised to remain cautious about fraud threats
Danish officials urged residents to stay vigilant against potential scams involving fraudulent calls, emails, or other messages exploiting exposed personal details. Citizens are advised never to share passwords or confidential information just because someone claims to know their name, address, or CPR number. The government recommended consulting official digital security resources and Denmark’s cyber hotline. The warning was issued after confirming that the breach involved data belonging to millions of individuals registered within the national population system.
Authorities are still evaluating the route of unauthorized access, the specific records affected, and the safeguards surrounding private company use of the CPR system. Separately, Datatilsynet is reviewing the data protection concerns raised by the incident. The CPR administration has revoked the company’s access and implemented security measures, while officials continue an extended review of the registry. As of Oct. 7, neither the attackers’ identities nor the private company’s name have been publicly disclosed, nor has the exact method used to misuse authorized access been confirmed.
