Denmark’s CPR Registry Data Breach Exposes Personal Information of 8.8 Million People
Denmark’s Central Population Registration Authority (CPR) has warned that a data breach compromised the personal information of approximately 8.8 million registered people.
The affected records include information belonging to people currently living in Denmark, people who have moved abroad, and people who have died.
What information was exposed?
Denmark’s CPR system is the country’s national civil registry. It contains personal information such as names, addresses, dates of birth, marital status, and unique CPR identification numbers.
According to the CPR announcement, threat actors exploited legitimate access to the registry system held by a Danish private company. They used that access to obtain names, addresses, CPR numbers, and other information about registered individuals.
The Danish Data Protection Agency said the attack likely involved some form of brute-force activity used to enumerate valid CPR numbers and extract information from individual records.
Most people in Denmark’s CPR system were affected
The CPR system currently holds data on approximately 11 million registered people. The incident therefore affected about 80% of those records, although not everyone was impacted.
The security incident occurred in September 2026. However, the CPR Administration did not become aware of the breach until October 2. Authorities determined the scale of the incident over the following weekend.
Authorities investigate the breach
The private company’s access to the registry has now been blocked, and police have launched an investigation that remains ongoing.
“This is a very serious incident, and we have also reported it to Parliament’s Business and Digitalization Committee,” said Christina Egerlund, Denmark’s Minister for Research, Education and Digitalization.
“We are working with all relevant authorities to determine the full extent of the incident.”
Egerlund said additional security measures are being implemented to prevent similar incidents involving CPR systems. She also urged the public to remain vigilant about unsolicited communications.
How affected individuals should protect themselves
A dedicated cyber hotline has been established for people who may be affected. Help and guidance are also available through sikkerdigital.dk.
“In light of this incident, we caution everyone to never disclose passwords or other sensitive information in response to telephone calls, emails, or similar communications,” the announcement warned.
“This also applies if the recipient appears to know your name, address, and CPR number.”
BleepingComputer has contacted authorities for additional information about the incident, including how the private company’s access was compromised, but had not received a response at the time of publication.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



