Skip to main content
Emerging ThreatsData Breaches

Denmark's Population Registry Breach Exposes 8.8 Million

Interior of Danish civic building with people in background and computer workstation in foreground.
"This is an extremely serious incident, which is why I have also informed Parliament’s Business and Digitalization Committee," stated Minister for Research, Education and Digitalization Christina Egelund.

Severity and scale inside Denmark's Central Population Register (CPR)

Denmark's Central Population Register (CPR) warns that a data breach exposed personal information for approximately 8.8 million registered individuals. The CPR is the nation's civil registry and currently holds data for 11 million registered citizens; roughly 80% of that dataset was affected, though not everyone listed in the register was impacted.

The exposed fields include names, addresses, dates of birth, marital status, and unique CPR identification numbers. The breach touches living residents, people who have moved abroad, and deceased individuals whose records remain in the registry.

Method of access: misuse of a private Danish company's legitimate access and brute-forcing

According to a CPR announcement published by the agency, threat actors misused a private Danish company's legitimate access to the registry system to obtain names, addresses, CPR numbers, and other information relating to registered members. A separate announcement by the Danish Data Protection Agency stated the attack involved "some form of brute-forcing to enumerate valid CPR numbers," and then extracting the related data from each entry.

At present the public record identifies two technical elements: the use of a legitimate external access path tied to a private company, and an enumeration technique described by the regulator as brute-forcing. The agency has not published a more detailed technical forensics timeline or a forensic report in the announcement cited by BleepingComputer.

Timeline: September breach, discovery on October 2, impact measured over the weekend

The security incident occurred in September 2026. CPR administration became aware of the breach on October 2 and determined the size of the impact over the subsequent weekend. The agency's public notice frames the sequence as an initial compromise or misuse in September followed by internal detection and an impact assessment completed early October.

BleepingComputer says it has contacted the agency to learn more about the incident — including how the private company was compromised — but had not received a response as of publication.

Government response: access blocked, police investigation, Parliament notified

After identifying the misuse, the CPR blocked the private company's access to the registry. Police have launched an investigation, which is currently underway. Minister Christina Egelund said additional security measures have been implemented to prevent similar incidents on the CPR system and that she has informed Parliament’s Business and Digitalization Committee.

Authorities set up a dedicated "cyber hotline" for potentially affected individuals and directed people to seek help and guidance online at sikkerdigital.dk. The official announcement also urged citizens to stay on high alert for unsolicited communications and reiterated a specific security warning: "In light of the incident, everyone is reminded never to disclose passwords or other confidential information in response to telephone calls, emails, or similar communications," the announcement warned. "This also applies even if the recipient appears to know your name, address, and CPR number."

What this means for technologists, policymakers, and the public

  • Technologists and security teams: The incident flags a risk vector tied to third-party or vendor access — specifically, legitimate access channels that can be misused — and a brute-force enumeration approach targeting national ID numbers. Security teams will be watching access governance, rate-limiting and anti-enumeration controls, and the mechanics of how that private company's credentials or permissions were abused.
  • Policymakers and regulators: The minister's decision to notify Parliament’s Business and Digitalization Committee signals the incident will be treated as a matter of public oversight. The Danish Data Protection Agency has already characterized the attack technique as enumeration via brute-forcing, information that could influence regulatory action or guidance on third-party access controls.
  • End users and the public: Roughly 8.8 million people are potentially affected. Authorities have provided a cyber hotline and an online resource at sikkerdigital.dk, and they have specifically warned the public not to disclose passwords or other confidential information even if a caller or message appears to know personal details such as name, address, and CPR number.

The immediate steps are now administrative and investigative: the private company's access has been blocked, a police investigation is under way, and authorities have implemented additional security measures while notifying Parliament. What remains publicly unanswered in the CPR and regulator statements is exactly how the private company's access was compromised and the full scope of extracted records beyond the approximate 8.8 million figure. For now, officials are directing affected people to the cyber hotline and sikkerdigital.dk and urging vigilance against unsolicited communications.

Original BleepingComputer report