Hackers access personal data for 8.8 million people in Denmark registry

The breach occurred during September, and the CPR administration learned of it on a Friday evening the following week, according to the ministry.
Authorities said names and addresses of people who had registered for name and address protection were not exposed in the review conducted so far.
The CPR can also hold details such as marital status, birth registration, family relationships, Church of Denmark affiliation and legal incapacitation, though officials had not specified whether any of these additional categories were accessed.
Digital affairs minister Christina Egelund said she had briefed the Folketing’s Business and Digitalisation Committee on the incident.
Hackers accessed personal information on 8.8 million people in Denmark by breaking into a company with authorized access to the country's Central Person Register. 24newshd reported that the stolen data includes names, addresses, and CPR identification numbers — affecting roughly 80% of Denmark's 11 million residents. The breach was discovered in September, though authorities didn't learn of it until the following week.
Officials are still investigating what information was accessed and whether it was misused. Bloomberg stated that the CPR database can hold details like marital status, family relationships, and Church of Denmark affiliation, though authorities haven't confirmed if these were exposed. Names and addresses of people who registered for privacy protection appear to have been safe, according to the ministry.
The attack exploited a legitimate access point. A Danish company had authorized permission to use the Central Person Register for lawful purposes — but hackers broke through that gateway to steal data. Business Standard confirmed that 8.8 million records were compromised, including people who have since died or moved abroad. The registry's total size is roughly 11 million people.
The breach exposed highly sensitive identifiers. Names, addresses, and CPR numbers — Denmark's equivalent of a Social Security number — were all stolen. These pieces of information make targets vulnerable to identity theft and fraud.Officials emphasized that people on the privacy protection registry were not exposed in the initial investigation.
Denmark's digital affairs ministry confirmed the incident and launched a formal investigation. Digital Affairs Minister Christina Egelund briefed parliament's Business and Digitalisation Committee on what happened. Authorities have already taken steps to restrict the breached company's access to the registry and prevent similar incidents.
Investigators are still determining the full scope of the damage. They're working to confirm whether other personal details — like marital status, birth records, or family relationships — were accessed. Officials have not yet announced what additional information may have been compromised beyond the confirmed names, addresses, and CPR numbers.
The Central Person Register is Denmark's master population database, holding records on roughly 11 million people. Beyond basic identifiers, it can store marital status, birth registration, family relationships, Church of Denmark affiliation, and legal incapacitation status. Companies get legitimate access to this data for lawful purposes — but this breach shows how authorization systems can be exploited by determined attackers.
The incident raises questions about government data security nationwide. An 8.8 million-person breach affects roughly 80% of Denmark's population, making it one of the largest data exposures in Nordic history. Authorities say they are reducing future risk, but officials have not detailed exactly how they plan to prevent hackers from exploiting legitimate access points again.
Publishers
15
Articles
30
Reach
45