Denmark confirms theft of CPR records affecting about 8 million people

Denmark has confirmed that hackers stole most of the contents of the country’s Central Person Register (CPR), exposing records relating to about 8 million citizens and residents. The breach included people living abroad and deceased individuals, while Denmark’s current population is about 6 million.
Minister Christina Egelund described the incident as serious. The stolen information includes names, addresses, Danish social security numbers and other data held in the CPR, the national register used for identity-related government services.
A national identity database was accessed through legitimate credentials
The intrusion occurred in September and was discovered on October 2. Danish authorities said the attackers gained unauthorized access by abusing a Danish company’s lawful ability to search for information in the CPR system.
Some companies are permitted to use the register to verify individuals’ information with the government. Authorities did not identify the party responsible for the attack or say how the authorized access was abused.
The CPR contains the government-issued identity number used in contexts including tax payments and access to other services. It holds records for around 11 million people, with some information dating back decades, which explains why the affected population is larger than the country’s present-day population.
Scale raises identity-data protection concerns
The Danish government considers the incident potentially the largest data breach in the country’s history. A compromise of names, addresses and national identity numbers can create long-lived exposure because the data supports identity verification across public and private services.
The case also illustrates a risk that extends beyond an internet-facing government system. A third party may need lawful access for a legitimate operational purpose, but that access can become a route to broad data extraction if searches, privileges and abnormal activity are not tightly controlled.
What organizations can take from the incident
Businesses that connect to government or identity-data services should inventory every third-party access path, limit permissions to the minimum required for verification, and monitor for unusual patterns such as high-volume searches. They should also ensure that access reviews and incident-response arrangements cover trusted partners, because lawful access can still be abused at scale.

