Drooid Logo
Back to story perspectives

Full Breakdown

Denmark’s Central Person Register Breach Exposes Data of 8.8 Million People

By Drooid · · How we work

Core Event: Unauthorized Access to the CPR Database

In September 2026, unauthorized individuals gained access to Denmark’s Central Person Register (CPR), extracting names, residential addresses and CPR numbers for approximately 8.8 million records. The breach was discovered on October 2 when the CPR administration detected irregular system activity, and the government announced the incident publicly on October 5. Investigators say the attackers did not break directly into the government’s servers; instead they misused the lawful access of a private Danish company that is authorized to query the CPR for business purposes. The company’s access has since been blocked, although some reports indicate the permission may still be active. No hacker group or individual has been identified.

Background & Context

The CPR is Denmark’s national civil-registration system, assigning every resident a unique ten-digit identifier used for taxes, health care, banking and other public services. While Denmark’s resident population is about six million, the register holds roughly 11 million entries because it also stores records of deceased persons and citizens who have emigrated. Under Section 38 of the Civil Registration Act, private firms with a legitimate interest may obtain limited CPR data, subject to GDPR and national data-protection rules. The breach highlights the risk that privileged third-party connections can become an attack vector even when the core database remains technically intact.

Data & Statistics

  • 8.8 million CPR records were accessed, representing the majority of the 11 million entries stored.
  • Denmark’s resident population is ? 6 million; the excess reflects historical and emigrant records.
  • The exposed fields include names, addresses and CPR numbers; additional details such as church membership, legal incapacitation status and family relationships may also have been accessed, according to Danish authorities.
  • Individuals who have registered for name- and address-protection were reportedly not affected.

Official Statements & Responses

Digital Affairs Minister Christina Egelund described the breach as “extremely serious” and ordered a comprehensive security review of the CPR system. The ministry has suspended the private company’s access and notified the Data Protection Authority. Authorities have also urged citizens to be vigilant against phishing attempts that could exploit the newly exposed personal data.

Verbatim Quotes

  • “This is an extremely serious incident,” — Christina Egelund, minister

The Danish government continues to assess the full scope of the breach, evaluate the adequacy of third-party access controls, and advise the public on protective measures against identity-theft risks arising from the exposed data.