COPENHAGEN, DENMARK / RankWire.AI / – Authorities in Denmark are probing a significant security breach involving the country’s Central Person Register. Personal information linked to approximately 8.8 million individuals was accessed without authorization, including names, addresses, CPR numbers, and related records. Officials explained that the intruders exploited a lawful access point granted to a private Danish company to search the CPR database. The CPR administration has since revoked the company’s access as officials investigate how the breach occurred.

The CPR administration detected suspicious activity on the evening of Oct. 2, following unusual search patterns observed during September. Over the weekend, authorities reviewed the activity and confirmed the extent of the unauthorized access. The Central Person Register holds around 11 million records, covering current residents, those who have moved abroad, and deceased individuals. Officials confirmed that the searches remained within the categories of information that private companies are permitted to access through authorized CPR services.
The identity of the perpetrator remains unknown, and Danish officials have not disclosed the private company whose authorized access was exploited. The CPR administration reported the incident to Datatilsynet, Denmark’s data protection authority, and police are now conducting investigations alongside other relevant agencies. The government stated that its review found no exposure of names or addresses protected under Denmark’s scheme for individuals with sensitive registration details.
Regulator scrutinizes automated search activities
Datatilsynet announced it received the incident report from the CPR register on Oct. 4. The authority described the case as involving an extremely high volume of automated searches against the CPR system, aimed at verifying valid CPR numbers, as detailed in the notification. The regulator is now investigating the circumstances, how the breach was possible, and who is responsible for processing the data involved. It assured that further information would be provided once there is a sufficient basis to do so.
Research, Education and Digitalisation Minister Christina Egelund characterized the incident as deeply serious and briefed Denmark’s Business and Digital Affairs Committee. She also mandated a comprehensive security review of the CPR system. The government has initiated measures to prevent recurrence, while the CPR administration is still mapping the sequence of events. Authorities emphasized that the investigation remains in its early stages and that technical assessments could clarify confirmed details further.
Public advised on fraud alert
Danish authorities have urged residents to stay vigilant against potential scams involving fraudulent calls, emails, and messages that may use exposed personal information. Officials emphasized that individuals should never share passwords or confidential data simply because a caller or sender appears to know their name, address, or CPR number. The government directed residents to consult official digital security guidance and Denmark’s cyber hotline. This warning followed confirmation that the unauthorized activity involved data belonging to millions of registered persons in the national population system.
Authorities continue to evaluate the method of access, the affected records, and the safeguards around private-sector use of the CPR system. Datatilsynet is conducting a separate review concerning the data protection issues raised by the incident. The CPR administration has suspended the company’s access and implemented security measures, while officials conduct a broader review of the registry. As of Oct. 7, the attackers have not been publicly identified, the company’s name remains undisclosed, and the specific method used to misuse authorized access has not been confirmed.
