About 8.8 million people — living and dead — had their names, addresses and personal identification numbers accessed, the Danish Ministry for Digitalisation said on October 5.
Scale and scope: how many CPR records were touched
The ministry's preliminary figure counts roughly 8.8 million registered people from the Central Person Register (CPR), out of about 11 million records in the register — roughly four in five entries. That total includes living residents, people who have moved abroad, the dead and other registered persons, the ministry said. The access reportedly stayed within the set of data private companies are allowed to receive and did not include names and addresses for people registered with name-and-address protection.
The register has recorded everyone who lives or has lived in Denmark since 1968; Denmark's population was just under 6 million at the start of 2025, according to Statistics Denmark, which underlines that the affected records are not limited to current residents.
How the access happened and immediate official responses
The ministry said attackers used a private Danish company's lawful right to query the CPR to obtain the records. The access ran for about 10 days in September and went through a small Danish company, Christina Egelund, the minister responsible for digitalisation, told the news agency Ritzau. An employee of the register's administration noticed unusual activity on Friday, October 2; over the following weekend the administration determined the likely scale and stopped the company's access.
The register's administration reported the case to Datatilsynet, Denmark's data protection authority, and police are investigating. Datatilsynet on October 5 said a very large number of automated lookups were made to identify valid CPR numbers; its account comes from the notification it received from the register on October 4. Datatilsynet added that it has not yet assessed the case and described the numbers as allegedly retrieved.
Egelund told Ritzau that the safeguards around this kind of access “had not been solid enough,” and agreed alarms should have triggered given the duration of the activity. The ministry has begun unspecified measures to prevent a repetition and the minister has requested a full security review of the register.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat the law and guidance allow: company access under the 2023 CPR Act
Under the 2023 wording of the CPR Act, companies may receive register data about people they have already identified one by one; a CPR number alone is enough to identify a person for that purpose. The data companies may get includes a person's current name and address — unless protected — and status details such as a death, a move abroad or a credit warning. The act's list does not include the CPR number itself.
The register's guidance says companies may only request data on people they already deal with, for example customers or employees. The ministry sets the terms for company access under the act, including required security measures; the official statements do not explain how one company's access came to cover roughly 80% of the register.
Practical steps issued to people with a CPR number
The ministry pointed people to the government advice site sikkerdigital.dk, which lists four fraud-guarding steps:
- Be extra alert to unexpected texts, calls and emails in which the sender uses details about you.
- Do not click links in unexpected messages; instead go to the official website yourself or call the sender's main number to check.
- Never share MitID details, one-time codes, passwords or card details.
- Set up a credit warning on borger.dk.
The government-run Cyberhotline for digital security on +45 33 37 00 37 was given extended opening hours — 8 a.m. to midnight — in the days after the announcement to help people follow these steps.
Details on the credit warning: it is a marker in the CPR that signals companies to take extra care before extending loans or credit in a person's name. The marker is registered immediately but can take days to propagate into companies' systems; anyone aged 15 or over can set one, and it can make loan applications harder to approve until removed. The register's official guidance also reiterates that a CPR number helps identify a person but must not be used as the only proof of identity.
What this means for technologists, regulators, and citizens
Technologists and security teams will focus on account-level access controls and monitoring: Datatilsynet said the lookups were automated, and the ministry has signalled that current safeguards were insufficient — both concrete prompts to review how company accounts are provisioned and watched under the ministry's rules.
Regulators and policymakers have active roles: Datatilsynet is examining what happened, how it could happen and who is responsible for handling the personal data; the register's administration reported the incident to Datatilsynet and police; and the minister for digitalisation has requested a full security review of the register's systems and terms for company access.
For ordinary people with a CPR number, the immediate course is practical: follow the four steps on sikkerdigital.dk, consider setting a credit warning on borger.dk, and use the Cyberhotline for help. The ministry has not said whether individuals will be told individually that they are among the roughly 8.8 million, nor whether affected people will need new CPR numbers; Egelund said it is too early to say, and the act already allows a new number in special cases where a number has been misused.
Three specific questions remain open in the official record: how the unauthorized parties gained access to the company's systems, whether they have retained or used the data, and who they are. Datatilsynet's examination, the police investigation and the minister's requested security review are the named next steps that will determine those answers.




