-
Unknown attackers misused a private company’s legal access to Denmark’s CPR database.
-
The breach exposed names, home addresses, and CPR numbers tied to 8.8 million records.
-
Denmark has ordered a full security review, and police are now investigating the case.
Denmark is looking into a serious security incident. Unauthorised people got hold of personal details tied to about 8.8 million people. The data came from the Central Person Register, known as CPR. This is Denmark’s main population database.
This number looks strange at first. Denmark only has around six million people. But the CPR system actually holds records for close to 11 million people. It tracks current residents, people who moved abroad, and even people who have died.
The attackers did not pull the whole database out in one go. Instead, they abused access that belonged to a private Danish company. That company had legal permission to search CPR records for its own work. Officials later cut off the company’s access while they looked into how it had been misused, according to the CPR authority.
Hackers Exploited a Legal Loophole to Access the Data
Under Danish law, some private companies can request CPR information for legal reasons. This system usually works well. But it also creates a weak point. If someone misuses that trusted access, they can reach huge amounts of personal data at once.
That appears to be exactly what happened here. The attackers did not break through a locked front door. They slipped through a side door that was already open for someone else. Danish outlet Ritzau reported that this raised fresh concerns about how much trust the system places in outside companies.
People who had signed up for name and address protection were not caught up in this part of the breach. Their protected details stayed hidden during the unauthorised searches, the CPR authority confirmed.
Denmark Spotted Unusual Activity in Early October
Officials first noticed something odd on the evening of October 2. After digging deeper, investigators found out that the unauthorized activity had actually started back in September.
Denmark’s Data Protection Agency received a formal report about the incident on October 4. The agency said attackers ran a huge number of automated searches. Their goal was to find valid CPR numbers one by one. The Data Protection Agency says it is now checking what happened, how it happened, and who was behind it.
So far, no one has named the people responsible. Officials also have not shared exactly how the attackers pulled off the access in technical terms. The case is still young, so some facts could shift as the investigation moves forward.
Euronews reported that Danish officials have called this one of the most serious data incidents the country has faced in years.
Officials Order a Full Security Review
Denmark’s Research, Education and Digitalisation Minister, Christina Egelund, called the breach deeply serious. She ordered a full review of security across the entire CPR system right away.
The government has already told the Data Protection Agency about the case. Police are now working with other authorities to investigate it properly. Officials have also rolled out new steps meant to block similar access problems while the investigation continues.
This breach shows a bigger risk hiding inside trusted systems. Other recent data-breach claims have involved even larger identity datasets, including the dark web seller claiming 195 million U.S. and Canadian ID records for sale at $90,000.
A company’s legal access can turn into a major leak if someone misuses it or if hackers slip inside that access. Sensitive government databases like CPR sit right at the center of that risk.
Authorities are now urging the public to stay alert. People should watch closely for phishing attempts and scam calls in the coming weeks. Officials specifically warned citizens never to share passwords or private details over the phone or by email. This applies even if the caller already seems to know their name, address, or CPR number, Ritzau reported.
Experts say attackers often use real personal details to make scam messages feel believable. A message that already knows your address feels more trustworthy than a random one. That trust is exactly what criminals try to exploit.
For now, the investigation stays open. Danish authorities still do not know exactly who carried out the attack. They also have not confirmed the full scope of what was exposed. More details are expected as the review continues in the coming weeks.
Residents affected by the breach are advised to stay cautious with any unexpected messages. Simple steps, like confirming a caller’s identity independently, can stop a scam before it starts. Denmark’s government says it will share updates as the investigation moves forward.