Unauthorized parties have gained access to the names, addresses, and personal identification numbers of approximately 8.8 million people, encompassing both living and deceased individuals, within Denmark’s national population register. The alarming security incident, which sent shockwaves through the Scandinavian nation’s digital infrastructure, was officially disclosed by the country’s digitalization ministry on October 5.

The breach occurred through the exploitation of a private Danish company’s lawful right to perform lookups in the Central Person Register, widely known by its Danish acronym, CPR. In the wake of the revelation, the digitalization ministry issued urgent warnings to citizens, advising them never to disclose passwords or other confidential information to anyone who calls or emails, even if the contacting party appears to possess accurate personal details or seems to know specific data points related to their identity.

Prompted by the unusual volume of traffic, the administration responsible for overseeing the register swiftly halted the implicated company’s access to the system. Furthermore, authorities formally reported the case to Datatilsynet, Denmark’s independent data protection authority, while law enforcement agencies launched an active criminal investigation into the matter.

According to a formal notice published by Datatilsynet on October 5, a remarkably large number of automated lookups were executed within the register in an apparent effort to identify valid personal identification numbers, commonly referred to as CPR numbers. The data protection authority’s initial account is based directly on the official notification it received from the register’s administration a day prior. As regulatory oversight proceeds, Datatilsynet has noted that it has not yet fully assessed the entire case, describing the compromised numbers as having been allegedly retrieved rather than definitively mapped out in a final audit.

Unfolding the Timeline and Scope of the Breach

The unauthorized access remained undetected for a troubling ten-day period throughout September, routing surreptitiously through a small, unidentified Danish company. Christina Egelund, the government minister holding responsibility for digitalization, revealed these details during a briefing with the Danish news agency Ritzau. The systematic intrusion was finally flagged on Friday, October 2, when an observant employee within the register’s administration noticed anomalous activity. Over the course of the subsequent weekend, the administration scrambled to investigate the anomaly, eventually realizing the staggering scale of the breach and determining how many individual records had been compromised.

Despite the swift containment measures, official statements from the government and regulatory bodies have left several critical questions wide open. Chief among these unresolved mysteries are how the unauthorized external parties managed to breach or compromise the company’s internal systems, whether the malicious actors have successfully retained, stored, or deployed the harvested data for nefarious purposes, and precisely who is behind the sophisticated operation.

Who Is Covered by the Compromised Register

The staggering figure of 8.8 million affected records stems from initial estimates provided by the digitalization ministry and remains subject to final verification. This broad count encompasses all categories of registered individuals, including currently living residents, citizens who have permanently moved abroad, deceased persons, and various other historical entries. To put the figure into perspective, Denmark’s official national population register holds records for approximately 11 million people in total. This means the unauthorized access successfully touched roughly four out of every five records contained within the massive repository.

Since its establishment in 1968, the Central Person Register has maintained continuous documentation of everyone who currently lives or has ever lived in Denmark. According to comprehensive data published by Statistics Denmark, the nation’s overall population stood at just under 6 million people at the beginning of 2025.

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Crucially, the digitalization ministry emphasized that the unauthorized access remained strictly confined within the boundaries of data categories that private companies are legally authorized to receive under normal operational circumstances. Significantly, the breach did not encompass the names and addresses of individuals who have specifically registered for name-and-address protection. In most standard legal cases, this specialized protective status acts as a formidable barrier, preventing the register from disclosing a citizen’s sensitive residential address or legal name to private commercial entities or individual inquirers.

However, the ministry’s public statements have notably omitted any clarification regarding whether the personal CPR numbers belonging to protected individuals were accessed during the automated lookups, or if affected citizens will receive direct, individual notifications informing them that they are among the 8.8 million people whose data was exposed.

Safeguarding Personal Information and Mitigating Fraud Risks

In response to the widespread anxiety caused by the data breach, the digitalization ministry has directed concerned citizens to the official government advisory portal, sikkerdigital.dk. The security platform outlines critical precautionary measures designed to help individuals guard against potential identity theft and digital fraud.

To assist citizens navigating the aftermath of the breach, the government-operated Cyberhotline for digital security extended its operating hours, providing specialized assistance via telephone at +45 33 37 00 37. During the days immediately following the public announcement, the help line maintained extended availability from early morning until midnight to handle the surge of inquiries.

Among the primary defense mechanisms available to citizens is a credit warning. This specialized marker can be placed directly into the CPR system, signaling to financial institutions and commercial enterprises that the holder wishes to be actively protected against companies extending loans or credit lines in their name. Functioning as a high-alert signal, businesses that choose to receive these warnings are instructed to exercise heightened scrutiny and take extra care when verifying a customer’s true identity before approving any financial lending.

According to guidelines published on borger.dk, the official public digital portal where individuals can activate the marker, a newly registered credit warning takes effect immediately within the system, though it can take a few days to propagate through the various commercial networks and reach individual corporate databases. Any citizen aged 15 or older possesses the legal right to establish a credit warning on their profile. While effective at thwarting fraudsters, setting this marker can also introduce temporary hurdles for the holder, potentially making legitimate loan applications harder to approve until the protective marker is officially removed.

Government guidelines consistently stress that while a CPR number serves as a vital identifier for an individual citizen, it must never be accepted as the sole proof of identity in financial or administrative transactions.

How Companies Obtain Access to the Register

Under the legal framework established by Denmark’s CPR Act, commercial enterprises are legally permitted to have specific register data delivered regarding individuals with whom they have already established a concrete, one-on-one business relationship. For this specific purpose, possessing a valid CPR number alone is deemed sufficient to identify the relevant person.

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

The specific categories of data that authorized companies are legally entitled to receive include a person’s current legal name and residential address—provided those details are not restricted by name-and-address protection—alongside pertinent status indicators such as notification of a death, a permanent move abroad, or the presence of an active credit warning. Interestingly, the foundational 10-digit CPR number itself is excluded from that specific delivery list.

Structurally, a Danish CPR number consists of 10 distinct digits: the first six digits represent the holder’s date of birth, followed by a four-digit serial number, where the final digit is mathematically even for women and odd for men. Analyzing this numerical architecture, industry observers note that the format permits a maximum of 10,000 possible serial combinations for any single date of birth. While Datatilsynet’s official notice confirmed that the automated lookups were executed precisely to identify valid numbers, neither the data protection authority nor the ministry’s statements have formally confirmed whether the perpetrators systematically cycled through those mathematical possibilities.

The official operating guidelines governing the register explicitly stipulate that companies may only request and receive data pertaining to individuals with whom they maintain a pre-existing, legitimate relationship, such as active customers or registered employees. Despite these stringent rules, official government statements have yet to explain how a single company’s authorized access under these statutory parameters managed to expand to encompass roughly 80 percent of all records held on the national register.

Under the provisions of the CPR Act, the specific ministry tasked with overseeing the register holds the authority to establish the exact terms and conditions governing corporate access, including mandatory cybersecurity measures. Minister Egelund acknowledged in her remarks to Ritzau that the existing safeguards surrounding this specific category of register access were simply not robust enough, concurring with critics that automated security alarms should have been triggered much sooner given the extended duration of the unauthorized activity.

Moving Forward and Investigating the Systemic Failure

In the wake of the crisis, the digitalization ministry has initiated corrective measures designed to prevent a recurrence of the security lapse, though specific details of these technical fixes were omitted from official briefings. Furthermore, Minister Egelund has formally requested a comprehensive, independent security review of the entire national population register to identify latent vulnerabilities.

Concurrently, Datatilsynet is pressing forward with its exhaustive regulatory examination to determine the exact sequence of events, analyze how the exploit was successfully executed, and establish clear accountability regarding the mishandling of sensitive personal data.

Addressing questions about long-term remediation, Egelund told Ritzau that it remained premature to speculate on whether citizens would ultimately require entirely new CPR numbers. Existing provisions within the national CPR Act already grant authorities the legal flexibility to issue replacement identification numbers in extraordinary cases where an individual’s existing number has been severely compromised or subjected to malicious misuse.

Leave a Reply

Your email address will not be published. Required fields are marked *