All stories
Security

Denmark's Central Population Register Suffers 'Deeply Serious' Data Breach Exposing 8.8 Million Records

A critical vulnerability in a third-party company's access led to the exposure of names, addresses, and unique CPR numbers for nearly 8.8 million people from Denmark's highly digitized Central Population Register, severely undermining digital trust in the nation.

By TECH NEWS Editorial·Source:TechCrunch·4 min read·33m ago

✨ This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Denmark's Central Population Register Suffers 'Deeply Serious' Data Breach Exposing 8.8 Million Records

Denmark's Central Population Register (CPR), a cornerstone of its highly digitized public sector, has suffered a "deeply serious" data breach, exposing the personal information of approximately 8.8 million people. The breach, confirmed by the Danish government on Monday, October 5, 2026, extends beyond Denmark's current population of roughly six million, encompassing records of individuals living abroad and those who are deceased, from a total register of about 11 million people. The compromised data includes names, addresses, and the unique 10-digit CPR numbers, which are akin to Social Security numbers in the U.S. and are widely used for healthcare, banking, and government services in Denmark.

This incident did not involve a direct hack of the CPR system's core infrastructure but rather the exploitation of a private Danish company's legitimate access to the database. Investigators determined that unauthorized parties misused this approved company connection to conduct automated searches and extract data during September 2026, with irregular activity first detected on Friday, October 2, 2026. Digitalization Minister Christina Egelund acknowledged that "security measures surrounding this company's access to CPR have not been good enough" and that warnings should have been triggered sooner given the activity continued for several days. The company's access has since been revoked, and a thorough security review of the CPR system has been ordered. The Danish Data Protection Agency was notified, and police are investigating, though no suspects have been identified yet. Individuals who had registered for name and address protection were reportedly not affected.

The implications of this breach are significant, striking at the heart of digital trust in a nation lauded for its advanced digitalization. Denmark consistently ranks high in digital government indices, scoring 0.83 in the 2025 OECD Digital Government Index, above the OECD average of 0.70, and is known for its "digital by default" approach to public services. The CPR number is a central identifier, and its compromise, combined with names and addresses, creates a fertile ground for sophisticated phishing attacks and identity theft. Cybersecurity experts, like Aarhus University professor Jens Myrup Pedersen, warn that such comprehensive data allows criminals to craft "more realistic attacks" that appear to originate from trusted authorities. While Denmark's reliance on two-factor authentication systems like MitID for sensitive digital actions offers some protection against direct impersonation with a CPR number alone, the stolen data can still be combined with other publicly available information to facilitate various forms of identity misuse, from fraudulent calls to potential financial scams.

This incident underscores the pervasive and evolving threat of supply chain attacks, where attackers leverage a trusted third-party's legitimate access to compromise a primary target. Dray Agha, senior manager of security operations at Huntress, highlighted this vulnerability, stating, "A compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure". This vector of attack has become a prominent concern, as evidenced by the UK Ministry of Defence payroll data breach in May 2024, which also originated from a third-party provider. Similarly, the 2015 Bundestag hack in Germany, attributed to Russia's GRU, involved spear-phishing to gain initial access, demonstrating how initial entry through seemingly smaller vulnerabilities can lead to widespread compromise of government systems. The Danish breach also echoes a 2021 incident in Argentina and a 2016 breach in Turkey, both involving population-scale compromises of national registries.

Denmark has actively pursued robust cybersecurity strategies, with the National Strategy for Cyber and Information Security 2026–2029 launched earlier this year, allocating DKK 211 million (approximately $30 million USD) for initiatives aimed at strengthening public-private cooperation, supporting SMEs, and enhancing citizen digital literacy. This strategy built upon the 2022-2024 strategy that allocated DKK 270 million to 34 key initiatives. However, this latest breach reveals a critical gap in oversight and enforcement, particularly concerning third-party access. The country's strong commitment to digitalization, while offering efficiency, also centralizes vast amounts of sensitive data, making such databases high-value targets.

Looking ahead, the immediate priority for Danish authorities is to complete the full mapping of the incident's extent, identify the perpetrators, and bolster the compromised systems. The Cyberhotline for digital security has already extended its operating hours from 8 a.m. to midnight to assist concerned citizens. Under GDPR and Danish data protection laws, the Data Protection Authority must be notified within 72 hours of awareness, and individuals must be notified without undue delay if there's a high risk to their rights and freedoms. The long-term implications, however, are more profound. The lifetime validity of CPR numbers means that the risks to affected individuals could be enduring. This incident will likely necessitate a fundamental re-evaluation of how governmental entities grant and monitor third-party access to critical national databases, emphasizing continuous monitoring over periodic audits. It serves as a stark reminder that even highly digitized nations with proactive cybersecurity strategies remain vulnerable to sophisticated attacks, particularly those exploiting the weakest links in the digital supply chain. The breach may also prompt a deeper debate on the inherent risks of highly centralized national databases and the balance between digital efficiency and robust data protection.

Sources