COPENHAGEN, DENMARK / RankWire.AI / – A major breach involving Denmark’s Central Person Register is now under investigation by Danish authorities. About 8.8 million individuals’ personal data was accessed unlawfully, including names, addresses, CPR numbers, and associated records. Officials confirmed that the attackers exploited legitimate access granted to a private Danish company to conduct searches within the CPR system. The CPR administration has temporarily revoked the company’s access while investigations determine how the breach occurred.

Irregular activity was detected by the CPR administration on the evening of Oct. 2, following unusual search patterns during September. Over the weekend, authorities examined the activity and verified the extent of the unauthorized access. The Central Person Register contains roughly 11 million records, which include information on current residents, those who have moved abroad, and deceased individuals. Officials clarified that the searches stayed within the scope of data that private companies are permitted to access via authorized CPR services.
The source of the activity remains unidentified, and Danish officials have not named the private company whose authorized access was exploited by the attackers. The CPR administration reported the incident to Datatilsynet, Denmark’s data protection authority, with police and other relevant agencies now involved in the investigation. The government stated that its review indicates no exposure of names and addresses protected under Denmark’s register protection scheme.
Regulator investigates automated searches in CPR system
Datatilsynet announced that it received the incident report from the CPR register on Oct. 4. The authority noted that the case involved a significant number of automated searches against the CPR system, aiming to verify valid CPR numbers, as stated in the notification. The regulator is now scrutinizing the details of what transpired, how the unauthorized access was possible, and who is responsible for handling the personal data involved. Further information will be provided once there is enough basis to do so, the agency indicated.
Research, Education and Digitalisation Minister Christina Egelund characterized the incident as highly serious, informing the parliament’s Business and Digital Affairs Committee. She also mandated a comprehensive security review of the CPR system. The government has initiated measures to prevent future breaches, while the CPR administration continues to piece together the sequence of events. Authorities noted that the investigation is still in its early stages, with the technical review likely to refine confirmed details.
Public advised to stay vigilant against fraud attempts
Danish authorities have urged residents to remain cautious of potential scams involving fraudulent calls, emails, or messages exploiting exposed personal information. Officials warned that individuals should never disclose passwords or other confidential data just because someone claiming to know their name, address, or CPR number contacts them. The government directed residents to official digital security guidance and Denmark’s cyber hotline. The warning followed confirmation that the unauthorized activity involved data belonging to millions of registered people in the national population system.
Authorities are continuing their assessment of the breach, focusing on the method of access, the affected records, and the safeguards around private-company use of the CPR system. Datatilsynet is separately reviewing the data protection concerns raised by the incident. The CPR administration has suspended the company’s access and implemented security measures, while officials conduct a broader review of the registry. As of Oct. 7, no publicly available information identified the attackers, named the private company involved, or confirmed the specific method used to misuse authorized access.
