Denmark Data Breach Exposes 8.8 Million People’s Personal Data

By Sara Sjolin | October 5, 2026

Denmark suffered a major data breach that gave unauthorized individuals access to names, addresses and personal identification numbers belonging to about 8.8 million people registered in the country’s central population database.

The breach occurred after unidentified individuals misused a private Danish company’s legitimate access to search the Central Person Register, known as CPR, the government said in a statement Monday.

The company has since been blocked from the system while police investigate the matter, with authorities saying it’s too early to determine who was behind the breach.

“This is a deeply serious incident,” Digitalization Minister Christina Egelund said. She has ordered a comprehensive security review of the CPR system and urged Danes to be vigilant about suspicious calls and emails.

The CPR system is a cornerstone of Denmark’s highly digitized public sector. Every resident is assigned a unique 10-digit CPR number that is widely used to identify individuals when dealing with government agencies, banks and healthcare providers. While Denmark has a population of about 6 million, the register contains records on roughly 11 million people, including those who have died or moved abroad.

The administration first detected irregular activity on Oct. 2 and determined over the weekend that unauthorized searches had taken place during September. People registered in the system for name and address protection weren’t exposed, it said.

Photo credit: Chris Ratcliffe/Bloomberg

Topics Cyber

Was this article valuable?

Here are more articles you may enjoy.