A massive data breach has rocked Denmark’s Central Person Register (CPR), leaving nearly 8.8 million people vulnerable to identity theft and other malicious activities. The incident is a stark reminder of the importance of robust cybersecurity measures, especially in critical infrastructure systems that handle sensitive personal information.
The CPR, established in 1968, serves as Denmark’s national civil registration system, containing details on approximately 11 million individuals, including residents, emigrants, and deceased persons. Hackers exploited a legitimate access point provided by a Danish company to exfiltrate sensitive data from the CPR system. This unauthorized access allowed them to obtain names, addresses, and CPR numbers of millions of registered individuals.
Under Danish law, private companies with a genuine interest in accessing individual information can do so through the CPR. However, this incident highlights how such legitimate access points can be exploited by malicious actors. The breach was detected on Friday after abnormal behavior within the system was reported during September. Following an immediate investigation, it was determined that hackers had accessed the sensitive data of approximately 8.8 million individuals.
Fortunately, those who chose to register with the name and address protection option are not affected by this incident. Nevertheless, the population register has urged all registered individuals to be cautious when receiving unsolicited communications requesting personal information, passwords, or other sensitive data.
In response to the breach, CPR has taken swift action by terminating the private company’s access and notifying the Danish Data Protection Agency and relevant authorities. An investigation is underway with law enforcement agencies to identify the threat actor responsible for the incident. The population register has also announced plans to review its security policies and implement additional measures to prevent similar incidents in the future.
This breach serves as a stark reminder of the importance of robust cybersecurity measures, especially in critical infrastructure systems handling sensitive personal information. It emphasizes the need for organizations to regularly review their security protocols and procedures to ensure that they are up-to-date with the latest threats and vulnerabilities.
As individuals, it is essential to remain vigilant when receiving unsolicited communications requesting sensitive data. Always verify the authenticity of such requests through trusted channels before providing any information. Additionally, keeping software up-to-date, using strong passwords, and being cautious when clicking on links or downloading attachments are crucial in protecting against cyber threats.
Source: SecurityWeek — 2026-10-06