Major Data Breach in Denmark’s National Database Affects 8.8 Million Residents
Denmark’s Central Population Register (CPR) experienced a security incident involving unauthorized retrieval of sensitive citizen data.
Incident Overview
The Danish Central Population Register (CPR) experienced a security incident involving the unauthorized retrieval of sensitive citizen data. The CPR administration identified irregularities in system activity during September 2026. Following investigation over the weekend, the extent of the breach was confirmed on Sunday, 4 October 2026, leading to immediate notification of the Danish Data Protection Agency (Datatilsynet).
Timeline of Events
The Danish Ministry of Research, Education and Digitalisation publicly disclosed the incident on 5 October 2026. The breach involved a private Danish company exploiting its authorized access to query the CPR system. Attackers obtained personal details including names, addresses, and CPR numbers by leveraging this legitimate access.
Breach Details
The company’s privileges were immediately revoked, and law enforcement agencies initiated a joint investigation with relevant authorities. No suspects have been identified at this stage, as the probe remains ongoing. The CPR database contains approximately 11 million records, with the breach impacting roughly 80% of the population.
Response and Investigation
The Danish Data Protection Agency has launched an inquiry to determine the circumstances of the incident, assess accountability for data processing, and evaluate preventive measures. The ministry issued warnings about potential fraudulent activities using the compromised data, advising citizens to avoid sharing passwords or confidential information through unsolicited communications.
Official Statements
Christina Egelund, Minister of Research, Education and Digitalisation, emphasized the severity of the breach, stating that authorities are actively investigating the full scope of the incident. She urged the public to remain vigilant and consult official resources at sikkerdigital.dk for updates.
Implications and Next Steps
The incident highlights vulnerabilities in third-party access controls and underscores the risks associated with data sharing between public and private entities. Further details about the breach’s technical mechanisms and investigative progress are expected as the inquiry advances.
