COPENHAGEN, DENMARK / RankWire.AI / – Authorities in Denmark are conducting an investigation into unauthorized access to personal information stored in the country’s Central Person Register, commonly known as CPR. The breach involved records linked to approximately 8.8 million individuals. The accessed data included names, addresses, CPR identification numbers, and other registered details. Officials confirmed that the attackers used credentials associated with a private Danish company that had legitimate permission to access the national population database. The company’s name has not been disclosed by authorities.

The CPR administration detected irregular activity on the evening of Oct. 2, following a series of searches in September. Over the subsequent weekend, officials examined the activity and determined the scope of the breach. The CPR database holds around 11 million entries in total, covering current residents, individuals who have moved abroad, and those who are deceased. Authorities emphasized that the searches stayed within categories of information accessible through authorized CPR services.
No individuals have been identified as responsible for the unauthorized searches. After discovering the suspicious activity, the CPR administration revoked the company’s access. Danish police and other officials are investigating how the breach occurred and which records were accessed. They also reviewed data protected under Denmark’s name and address protection scheme. It was confirmed that protected names and addresses under that scheme were not part of the compromised information.
Data watchdog assesses automated searches on CPR system
Datatilsynet, Denmark’s data protection authority, received the incident report on Oct. 4. The agency indicated that a significant number of automated searches had targeted the CPR database. The notification stated these searches aimed to verify the validity of CPR numbers. Datatilsynet is now investigating how unauthorized parties gained access and what personal data was retrieved. The review also includes assessing responsibility for handling the affected data under Danish data protection regulations.
Research, Education and Digitalisation Minister Christina Egelund described the incident as extremely serious and informed Denmark’s Business and Digital Affairs Committee. She ordered a comprehensive security assessment of the CPR system and its access controls. The government has also initiated measures to prevent similar incidents in the future. Authorities continue to trace the sequence of events and evaluate the safeguards used by private entities with authorized access to CPR data.
Public advised to remain vigilant against potential scams
Danish officials advised residents to be cautious of fraudulent calls, emails, and messages that might include exposed personal information. They warned people not to share passwords or confidential data, especially if a caller claims to already know their name, address, or CPR number. The government recommended consulting official digital security resources and Denmark’s cyber hotline. There has been no confirmation that the accessed data was used for fraud, identity theft, or other criminal activities beyond the unauthorized searches.
Investigators are still examining how the breach happened, which records were affected, and the security measures in private use of the CPR system. The identity of the private company involved and the specific method of misuse remain undisclosed. Authorities have not publicly identified those responsible for the searches. As of Oct. 7, the CPR administration, police, and regulators continued separate investigations into the incident, while Denmark assessed the security of its national population register.
