COPENHAGEN, DENMARK / RankWire.AI / – A significant security lapse has been identified by Danish officials within the country’s Central Person Register, with unauthorized individuals gaining access to personal details of approximately 8.8 million citizens. The compromised data encompassed names, addresses, CPR numbers, and related records. Officials confirmed that the attackers exploited a lawful connection maintained by a private Danish firm to search the CPR system. As a precaution, the CPR authority has suspended this company’s access pending further investigation into how the breach occurred.

Irregular activity was detected by the CPR administration on the evening of Oct. 2, following unusual search patterns observed during September. Over the weekend, authorities reviewed the incident and validated the extent of unauthorized access. Denmark’s Central Person Register holds around 11 million records, including data on current residents, individuals who have moved abroad, and deceased persons. Officials emphasized that the searches remained within the scope of information that private companies are legally permitted to access via authorized CPR services.
The identity of those responsible for the activity remains unknown, and Danish authorities have not disclosed the private company whose authorized access was exploited. The CPR administration reported the incident to Datatilsynet, Denmark’s data protection agency, and police are actively investigating alongside other relevant entities. The government also stated that its review found no evidence of personal names and addresses protected under Denmark’s name and address protection scheme being exposed.
Regulator investigates large-scale automated searches of CPR data
Datatilsynet announced receiving the incident report from the CPR register on Oct. 4. The authority described the case as involving an extensive number of automated queries directed at the CPR system, with the intent to verify valid CPR numbers, according to the notification. The regulator is now examining the circumstances surrounding the breach, how access was gained, and who might be responsible for processing the personal data involved. Further details will be provided once sufficient information has been gathered, they stated.
Research, Education and Digitalisation Minister Christina Egelund characterized the incident as highly serious and briefed Denmark’s Business and Digital Affairs Committee in parliament. She also mandated a comprehensive security review of the CPR system. The government has initiated measures aimed at preventing similar breaches, while the CPR administration continues to reconstruct the sequence of events. Authorities noted that the investigation remains in its early stages and that ongoing technical assessments could adjust some of the initial findings.
Officials warn the public to be vigilant against fraud
Residents of Denmark have been advised by authorities to stay alert for scam calls, emails, and messages that may leverage exposed personal information. Officials emphasized that individuals should never disclose passwords or other sensitive data merely because someone claiming to know their name, address, or CPR number contacts them. The government directed citizens to official digital security resources and Denmark’s cyber hotline for assistance. This warning came after confirmation that the unauthorized access involved data belonging to millions registered in the national population system.
Authorities are still evaluating the method of access, the affected records, and the safeguards related to private companies’ use of the CPR system. Separately, Datatilsynet is reviewing the data protection implications of the incident. The CPR administration has halted the private company’s access and implemented security measures as officials conduct an expanded review of the database. As of Oct. 7, authorities have not publicly identified the perpetrators, disclosed the name of the involved company, or confirmed the exact technique used to abuse the authorized access.
