COPENHAGEN, DENMARK / RankWire.AI / – A significant security breach involving Denmark’s Central Person Register is under further investigation by Danish authorities. Personal data associated with approximately 8.8 million individuals was accessed without authorization. The compromised information comprised names, addresses, CPR numbers, and related records. Officials clarified that the perpetrators exploited legitimate access granted to a private Danish company to perform searches within the CPR system. In response, the CPR administration has suspended this company’s access while the authorities examine the circumstances of the breach.

On the evening of October 2, the CPR administration identified suspicious activity after observing unusual search patterns during September. Over the weekend, authorities analyzed this activity, confirming the extent of the unauthorized access. The Central Person Register contains about 11 million records, including data on current residents, individuals who have moved abroad, and deceased persons. Officials emphasized that the searches remained within the categories of information that private companies are legally permitted to access through authorized CPR services.
To date, the investigation has not determined who carried out the activity. Danish officials also have not disclosed the name of the private company whose authorized access was exploited by the attackers. The CPR administration reported the incident to Datatilsynet, Denmark’s data protection authority, and police are conducting an investigation with other relevant agencies. The government stated that its review found no exposure of names and addresses belonging to individuals registered under Denmark’s name and address protection scheme.
Regulator scrutinizes automated searches within CPR system
Datatilsynet announced it received the report about the incident from the CPR register on October 4. The authority described the case as involving a very large volume of automated searches targeting the CPR system. These searches aimed to verify the validity of CPR numbers, according to the notification. The regulator is examining the details of what transpired, how the unauthorized access was enabled, and who might be responsible for handling the personal data. It added that further information would be provided when sufficient basis exists for disclosure.
Research, Education and Digitalisation Minister Christina Egelund described the incident as deeply serious and briefed Denmark’s parliament’s Business and Digital Affairs Committee. Additionally, she ordered a comprehensive security review of the CPR infrastructure. The government has initiated measures to prevent recurrence, while the CPR administration continues to trace the sequence of events. Authorities noted that the investigation remains at an early stage, and technical assessments may refine the understanding of the incident’s details.
Official warnings issued to public regarding potential fraud threats
Danish authorities advised residents to stay vigilant against scam calls, emails, and messages that might leverage exposed personal data. Officials cautioned that individuals should never share passwords or other sensitive information simply because someone claiming to know their name, address, or CPR number contacts them. The government recommended consulting official digital security resources and Denmark’s cyber hotline for guidance. This warning followed confirmation that the unauthorized activity involved data belonging to millions registered within the national population registry.
Authorities are still evaluating the method of access, the records affected, and the safeguards related to private company use of the CPR system. Separate from this, Datatilsynet is reviewing the data protection implications of the breach. The CPR administration has disabled the private company’s access and implemented security measures, as officials conduct a broader investigation into the registry. As of October 7, authorities had not publicly identified the perpetrators, disclosed the company’s name, or confirmed the precise means by which the unauthorized access was executed.
