COPENHAGEN, DENMARK / RankWire.AI / – Danish authorities are probing a significant intrusion into the country’s Central Person Register. Unauthorized actors gained access to personal data of roughly 8.8 million individuals, including names, addresses, CPR numbers, and related records. Officials stated that the attackers exploited lawful access granted to a private Danish firm to search the CPR system. As a precaution, the CPR administration has revoked the company’s access while investigations into the incident progress.

The CPR administration identified suspicious activity on the evening of Oct. 2, following unusual search patterns observed throughout September. Over the weekend, authorities examined this activity and verified the extent of the unauthorized access. The Central Person Register holds around 11 million records, covering current residents, those who have moved abroad, and deceased individuals. Officials emphasized that the searches fell within the categories of data legally accessible by private companies through authorized CPR services.
At this stage, the investigation has not determined who was responsible for conducting the activity. Danish officials have also not disclosed the private company whose lawful access was exploited. The CPR administration reported the breach to Datatilsynet, Denmark’s data protection authority, and police are working with other relevant agencies. The government stated that its review found no exposure of names and addresses protected under Denmark’s name and address safeguard scheme.
Regulator assesses automated CPR queries
Datatilsynet reported receiving the incident notification from the CPR register on Oct. 4. The authority explained that the case involved a very large volume of automated searches against the CPR system, which aimed to identify valid CPR numbers, as indicated in the notification. The regulator is investigating the circumstances leading to the breach, how the access was enabled, and who is accountable for processing the personal data involved. It pledged to release further details when a sufficient understanding is achieved.
Research, Education and Digitalisation Minister Christina Egelund described the incident as deeply serious and briefed Denmark’s Business and Digital Affairs Committee. She also mandated a comprehensive security assessment of the CPR system. The government has initiated measures to prevent future incidents, while the CPR administration continues to piece together the sequence of events. Officials emphasized that the investigation remains at an early stage, and technical reviews could clarify certain details further.
Public urged to stay vigilant against fraud
Danish authorities urged residents to stay alert for scam calls, emails, and messages that might utilize exposed personal information. Officials advised that individuals should never reveal passwords or other sensitive data just because a caller or sender knows their name, address, or CPR number. The government directed residents toward official digital security guidance and Denmark’s cyber hotline. The warning followed confirmation that the breach involved data belonging to millions registered in the national population system.
Authorities are still assessing how the intruders accessed the records, what data was affected, and the safeguards surrounding private-company use of the CPR system. Datatilsynet is independently reviewing the data protection implications raised by the incident. The CPR administration has cut off the company’s access and implemented security measures, while officials conduct a broader review of the registry. As of Oct. 7, the attackers’ identities, the company’s name, and the precise method used to exploit authorized access have not been publicly disclosed.
