Denmark population registry data breach affects 8.8 million people

A massive data breach has struck Denmark’s Central Population Register (CPR), exposing the personal information of a staggering 8.8 million registered individuals, including citizens who live in the country, those who have moved abroad, and even deceased people. The incident is considered extremely serious by Danish authorities, who are urging citizens to remain vigilant against potential follow-up attacks.

The CPR system contains sensitive data on residents, including names, addresses, dates of birth, marital status, and unique identification numbers known as CPR numbers. Threat actors exploited a private Danish company’s legitimate access to the registry system, using some form of brute-forcing to extract valid CPR numbers and then obtain related information from each entry. The breach occurred in September 2026 but wasn’t discovered until October 2, when the CPR administration became aware of the issue.

The security incident has significant implications for Denmark’s citizens. With 80% of the country’s registered population affected, a large number of people will be on high alert for unsolicited communications that may attempt to exploit their sensitive information. The Danish government has implemented additional security measures to prevent similar incidents in the future and is working closely with relevant authorities to establish the full extent of the breach.

The incident also highlights the importance of robust cybersecurity practices, particularly when it comes to protecting sensitive data. In this case, a private company’s access to the registry system was compromised, allowing threat actors to exploit the vulnerability. The government has since blocked the company’s access and launched an investigation into the matter. Minister for Research, Education and Digitalization Christina Egelund has stated that extra security measures have been put in place to prevent similar incidents on the CPR system.

Citizens are advised to remain cautious and not disclose any sensitive information in response to unsolicited communications, even if they appear legitimate. A dedicated “cyber hotline” has been set up for potentially affected individuals, and help and guidance are available online at sikkerdigital.dk. This is a timely reminder of the importance of protecting personal data and staying vigilant against potential cyber threats.

As the investigation continues, it’s essential for citizens to be aware of their surroundings and take proactive steps to protect themselves from potential follow-up attacks. By being informed and taking necessary precautions, individuals can minimize the risk of falling victim to such incidents.


Source: Bleeping Computer — 2026-10-05