COPENHAGEN, DENMARK / RankWire.AI / – Danish officials are expanding their inquiry into a significant breach involving the country’s Central Person Register. Unauthorized entities gained access to personal information related to approximately 8.8 million individuals, including names, addresses, CPR numbers, and associated records. Authorities stated that the hackers exploited a private Danish company’s legitimate access to the CPR system to conduct searches. The CPR administration has suspended the company’s access while investigations are ongoing to determine how the breach occurred.

The CPR authority identified suspicious activity on the evening of Oct. 2, after detecting unusual search patterns during September. Over the weekend, officials reviewed the activity and confirmed the extent of unauthorized access. The Central Person Register holds roughly 11 million records, encompassing current residents, expatriates, and deceased persons. Officials emphasized that the searches fell within the categories of information that private firms are legally permitted to access via authorized CPR services.
No attribution has yet been made regarding who carried out the activity, and Danish authorities have not disclosed the identity of the private company whose lawful access was exploited by the attackers. The CPR administration notified Datatilsynet, Denmark’s data protection agency, and law enforcement agencies are collaborating with other relevant authorities on the investigation. The government stated that its review found no exposure of names and addresses protected under Denmark’s name and address protection scheme.
Regulatory body investigates automated searches in CPR system
Datatilsynet reported receiving the incident notification from the CPR register on Oct. 4. The agency indicated that the case involved a substantial number of automated searches against the CPR system, which were intended to verify valid CPR numbers according to the report. The regulator is now examining how the breach happened, the means by which the access was obtained, and who might be responsible for processing the personal data involved. It added that further information would be provided once there is enough evidence to do so.
Research, Education and Digitalisation Minister Christina Egelund described the incident as extremely serious and briefed the parliament’s Business and Digital Affairs Committee. She also mandated a comprehensive security review of the CPR system. The government has initiated measures to prevent future breaches, while the CPR administration continues to piece together the sequence of events. Officials noted that the investigation is still in its early stages, and the technical review may lead to more precise details emerging.
Authorities caution the public against potential fraud risks
Danish authorities advised residents to stay vigilant regarding fraudulent calls, emails, and other messages that could leverage the exposed personal data. They emphasized that individuals should never disclose passwords or other sensitive information simply because someone claiming to know their name, address, or CPR number contacts them. The government directed citizens toward official digital security guidance and Denmark’s cyber hotline. This warning came after confirmation that the unauthorized activity involved data belonging to millions of registered individuals in the national population system.
Authorities continue to evaluate the method of access, the affected records, and the safeguards regulating private-company use of the CPR system. Datatilsynet is separately reviewing the data protection implications of the breach. The CPR administration has halted the company’s access and implemented security measures, while officials conduct a broader review of the registry. As of Oct. 7, authorities had not publicly identified the perpetrators, named the private firm involved, or confirmed the specific means by which the unauthorized access was exploited.