Denmark Population Registry Data Breach Affects 8.8 Million People
Denmark Population Registry Data Breach Affects 8.8 Million People
Denmark’s Central Population Register (CPR) has issued a warning regarding a significant data breach that has compromised the personal information of approximately 8.8 million registered individuals. This breach affects not only residents of Denmark but also individuals who have moved abroad and even deceased persons. The CPR serves as the national civil registry, containing vital information such as names, addresses, dates of birth, marital status, and unique CPR identification numbers. Currently, the CPR system holds data for 11 million registered citizens, meaning this incident impacted a substantial portion (80%) of that total.
According to a recent announcement from the CPR, threat actors exploited a private Danish company’s legitimate access to the registry system to obtain sensitive information, including names, addresses, CPR numbers, and other details related to registered members. A separate statement from the Danish Data Protection Agency revealed that the attack involved a form of brute-forcing to enumerate valid CPR numbers and subsequently extract the associated data from each entry. The security incident occurred in September 2026, although the CPR administration became aware of the breach on October 2 and assessed the extent of the impact over the following weekend.
In response to this alarming breach, access to the registry by the private company has been revoked, and an investigation by the police is currently underway. Minister for Research, Education, and Digitalization, Christina Egelund, emphasized the seriousness of the incident, stating, “This is an extremely serious incident, which is why I have also informed Parliament’s Business and Digitalization Committee.” Egelund also mentioned that additional security measures have been implemented to prevent similar occurrences in the future.
Furthermore, Egelund has urged citizens to remain vigilant against unsolicited communications. A dedicated cyber hotline has been established for potentially affected individuals, and help and guidance are available online at sikkerdigital.dk. The announcement cautioned, “In light of the incident, everyone is reminded never to disclose passwords or other confidential information in response to telephone calls, emails, or similar communications.” It further emphasized that this advice applies even if the recipient appears to know your name, address, and CPR number.
For more detailed information, you can read the full article here.