Denmark population registry data breach affects 8.8 million people

Denmark’s Central Population Register has suffered a massive data breach, exposing the personal information of approximately 8.8 million registered individuals. This includes people who live in Denmark, those who have moved abroad, and even deceased individuals. The affected data encompasses names, addresses, dates of birth, marital status, and unique identification numbers assigned to each citizen.

The Central Population Register is the country’s national civil registry, containing sensitive information on residents. A private Danish company had legitimate access to the registry system, but threat actors exploited this vulnerability to obtain a large portion of the data. According to the Danish Data Protection Agency, the attackers employed a technique known as brute-forcing to enumerate valid identification numbers and then extract related data from each entry.

The security incident occurred in September 2026, but it wasn’t until October 2 that the Central Population Register administration became aware of the breach. Over the weekend, they determined the extent of the impact, which affected a staggering 80% of the registry’s 11 million registered citizens. The private company’s access to the system has since been blocked, and police have launched an investigation.

Minister for Research, Education, and Digitalization Christina Egelund described the incident as “extremely serious” and vowed to take swift action to prevent similar breaches in the future. Additional security measures have been implemented on the Central Population Register system, and citizens are advised to remain vigilant against unsolicited communications. A dedicated cyber hotline has been established for those who may be affected, with online resources available at sikkerdigital.dk.

In light of this incident, it’s essential to remember that sensitive information should never be disclosed in response to telephone calls, emails, or similar communications – regardless of how convincing the recipient may appear to be. This is a crucial reminder for all individuals, as the personal data of 8.8 million people has been compromised.

In practical terms, this breach serves as a stark reminder that even seemingly secure systems can be vulnerable to exploitation. It’s essential for both individuals and organizations to stay informed about potential security threats and take proactive measures to protect their sensitive information. By staying vigilant and up-to-date with the latest cybersecurity best practices, we can all contribute to preventing similar incidents in the future.


Source: Bleeping Computer — 2026-10-05