Skip to content
TrustList
News

Attackers used a firm's access to take 8.8 million Danish CPR records

Editorial

By TrustList Editorial

The data covers living, emigrated and dead people, about 80% of the register. Datatilsynet received the breach notification on 4 October and has not yet said who is responsible.

About Attackers used a firm's access to take 8.8 million Danish CPR records

Attackers used a firm's access to take 8.8 million Danish CPR records

5 October 2026: Danish authorities say attackers misused a private company's legitimate access to the Central Population Register (CPR) to collect names, addresses and CPR numbers for about 8.8 million people. That is roughly 80% of the 11 million records in the system, and it includes people who live in Denmark, people who have emigrated and people who have died.

The ministry responsible says the incident happened in September. According to BleepingComputer's account, the register's administration learned of it on 2 October and worked out the scale over the following weekend. The company's access has been blocked, police are investigating together with the relevant authorities, and a security review of the whole CPR system is under way. People who are registered under name and address protection are not among those whose data was taken, the ministry says.

The Danish Data Protection Agency, Datatilsynet, received the register's breach notification on Sunday 4 October. It describes a very large number of automated lookups made to identify valid CPR numbers, and says it is still examining what happened, how it was possible and who is responsible for the processing of the personal data. It has said it will comment further when there are grounds to do so.

Minister Christina Egelund has called the incident extremely serious and informed the parliamentary committee for business and digitalisation. The cyber hotline for people who may be affected now runs from 8am to midnight, and guidance is published on sikkerdigital.dk. The ministry warns citizens that a caller or email that knows their name, address and CPR number is not for that reason genuine, and that passwords and other confidential details must never be given out in reply.

The announcement does not name the company or say how its access was obtained. BleepingComputer's request for those details had not been answered when it published.

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy