Skip to main content
Emerging ThreatsData Breaches

Danish ID Register Breach Exposes 8.8 Million Records

A lone figure sits at a desk in front of a blurred database representation, with a brightly-lit office or secure facility…

"Treating CPR numbers as secrets was a 'broken' approach."

Central Population Register (CPR): scale, content, and why the numbers exceed Denmark's population

The CPR administration said it became aware on October 2 of irregular activity in the country's Central Population Register during September and established the scale of the breach over the weekend. Approximately 8.8 million people had names, addresses, identification numbers and other personal information exposed, the administration said.

The ministry clarified that the register contains approximately 11 million records — a total that includes people who have died or moved abroad — and that explains why the number of affected records exceeds Denmark's current population of around 6 million. The database also includes information for more than 55,000 people living in Greenland who use CPR numbers for healthcare, tax services and banking.

The CPR administration noted that names and addresses of persons who chose to register with name and address protection were not exposed.

How a private company's legitimate access was abused and the legal framework invoked

The incident stemmed from an unauthorized party abusing a private Danish company's legitimate access to the CPR. The administration described the company whose access was abused as "small." Private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions set out in the ministry's access terms.

Those rules limit access to a defined group of people identified individually in advance and require recipients to be legally entitled to process the information under the GDPR and Danish data protection law. The Register has asked the ministry why such broad access was given in this case.

Immediate response: blocking access, specialists engaged, notifications and an active police investigation

After detecting the irregular activity, the CPR administration blocked the unnamed company's access and said it was working with specialists and relevant authorities to establish what happened. The administration has notified the Danish Data Protection Agency, and police are investigating.

The administration communicated these steps in a statement (PDF) detailing discovery and containment. The sequence presented — detection in September, discovery on October 2, weekend work to establish scale — frames an unfolding incident response that is now coordinated with regulators and law enforcement.

Digitization minister Christina Egelund and the debate over reissuing CPR numbers

Digitization minister Christina Egelund told television viewers it was too soon to say whether the country would issue all-new CPR numbers, a mitigation option proposed after the breach. The minister has publicly described the company whose access was abused as "small."

Separately, Danish cybersecurity specialist Jan Kaastrup told TV 2 that treating CPR numbers as secrets was a "broken" approach and argued that a number alone should not be accepted as proof of identity. He framed the incident as a prompt for better identification systems in a digitalized society.

What this means for technologists, policymakers, and the public

  • Technologists and security teams — Expect scrutiny on identity models: Kaastrup's comment that a number alone should not serve as proof of identity points to pressure for stronger authentication systems and a reassessment of how CPR numbers are used in digital services.
  • Policymakers and regulators — Questions over access policy are immediate: the Register has formally asked the ministry why broad access was granted under section 38(1), and the Data Protection Agency has been notified; decisions on whether to reissue CPR numbers will require weighing disruption against protection.
  • The public and affected individuals — Personal data for roughly 8.8 million records were exposed, though those registered with name and address protection were spared; the inclusion of deceased persons and those abroad helps explain the larger dataset but does not reduce the exposure of living residents and Greenlandic users who rely on CPR numbers for essential services.

The CPR administration has taken containment steps and engaged authorities; police are now investigating. Whether the state pursues structural changes — from more restrictive access controls under existing law to the politically and technically fraught option of issuing new CPR numbers — is the central policy question left in the wake of the breach.

Source: The Register — Denmark's ID register spills more people's details than the country has residents

Danish ID Register Breach Exposes 8.8 Million Records | OSINTSights