COPENHAGEN, DENMARK / RankWire.AI / – In Denmark, authorities have initiated a comprehensive investigation into a significant breach involving the country’s Central Person Register. Around 8.8 million individuals’ personal data was accessed without authorization. The compromised data comprised names, addresses, CPR numbers, and related information. Officials explained that the attackers exploited a private Danish company’s lawful access to search the CPR database. As a precaution, the CPR administration has halted the company’s access while investigations determine the breach’s root cause.

The incident came to light late on Oct. 2, after irregular activity was detected following unusual search patterns that occurred throughout September. Over the weekend, authorities analyzed the activity and confirmed the extent of the unauthorized access. The Central Person Register holds approximately 11 million records, including data on current residents, individuals who have moved abroad, and deceased persons. Officials clarified that the searches remained within categories of information legally accessible to private companies via authorized CPR services.
To date, no individual or entity has been identified as responsible for the activity. Danish officials have also refrained from naming the private company whose authorized access was exploited. The CPR administration reported the breach to Datatilsynet, Denmark’s data protection authority, and law enforcement agencies are now conducting further inquiries. The government assured that its review found no exposure of names and addresses protected under Denmark’s name and address protection scheme.
Regulatory body investigates automated searches within CPR system
Datatilsynet confirmed it received the incident report from the CPR registry on Oct. 4. The authority noted that the case involved an exceptionally high volume of automated queries targeting the CPR system. These searches were reportedly conducted to verify valid CPR numbers, according to the notification. The agency is now examining the details of what transpired, how the unauthorized access was enabled, and who might be accountable for processing the involved personal data. Further information will be provided by the regulator once enough evidence is collected.
Research, Education and Digitalisation Minister Christina Egelund described the incident as highly serious and briefed Denmark’s Business and Digital Affairs Committee. Additionally, she ordered a comprehensive security review of the CPR system. The government has initiated measures to prevent similar occurrences in the future, while the CPR administration continues to trace the sequence of events. Officials emphasized that the investigation is still in its early stages, and the technical review may refine some of the confirmed details.
Public advised to be vigilant against fraud schemes
Authorities in Denmark have called on residents to be cautious of scam attempts, including fraudulent calls, emails, and messages that may use personal information obtained from the breach. Officials strongly advised against sharing passwords or other sensitive data, even if the caller or message sender appears to know their name, address, or CPR number. The government directed individuals to official digital security resources and Denmark’s cyber hotline. This warning was issued after confirmation that the data involved millions of registered individuals in the national population system.
Authorities continue examining the method of access, the affected records, and the safeguards surrounding private companies’ use of the CPR database. Meanwhile, Datatilsynet is separately reviewing the privacy implications of the breach. As of Oct. 7, officials had not publicly identified the attackers, named the private company involved, or disclosed the specific technique used to misuse the authorized access. The CPR administration has suspended the company’s access and implemented security measures as part of a broader review of the registry.
