COPENHAGEN, DENMARK / RankWire.AI / – A significant breach involving Denmark’s Central Person Register is now under further scrutiny by Danish authorities. Personal information related to approximately 8.8 million individuals was accessed without authorization. The compromised data included names, addresses, CPR numbers, and associated records. Officials explained that the perpetrators exploited lawful access granted to a private Danish firm to search the CPR system. As a precaution, the CPR administration has revoked the company’s access while investigations are ongoing to determine how the breach occurred.

The CPR administration identified unusual activity on the evening of Oct. 2, following suspicious search patterns detected in September. Over the weekend, authorities examined the activity and verified the extent of the unauthorized access. The Central Person Register holds around 11 million records, covering current residents, individuals who have moved abroad, and those deceased. Officials confirmed that the searches were confined to information categories that private companies are legally permitted to access via authorized CPR services.
The identity of the individuals behind the activity remains unknown, and Danish officials have yet to disclose the private company whose lawful access was exploited. The CPR administration notified Datatilsynet, Denmark’s data protection authority, and police are collaborating with other relevant agencies to investigate. The government assured that its review did not reveal any exposure of names or addresses protected under Denmark’s privacy schemes.
Regulatory Authority Investigates Automated CPR Data Queries
Datatilsynet reported receiving the incident notification from the CPR register on Oct. 4. The agency indicated that the case involved a very large volume of automated searches against the CPR system, which aimed to verify the validity of CPR numbers according to the notification. The regulator is currently examining how the breach occurred, how access was gained, and who is responsible for handling the personal data involved. Further details will be shared once sufficient information is available, the authority stated.
Research, Education and Digitalisation Minister Christina Egelund described the incident as highly serious and briefed Denmark’s Business and Digital Affairs Committee. She also announced the launch of a comprehensive security review of the CPR system. The government has initiated measures to prevent future breaches, while the CPR administration continues to piece together the sequence of events. Authorities mentioned that the investigation is still in its early stages and that technical assessments may refine existing findings.
Public Advisories on Fraud Prevention Issued by Authorities
Danish officials have advised residents to stay vigilant against scams that may utilize exposed personal data through calls, emails, or other messaging methods. People are warned not to disclose passwords or other sensitive information just because a caller or sender appears to know their name, address, or CPR number. The government recommended consulting official digital security guidance and Denmark’s cyber hotline for assistance. This advisory came after confirmation that the unauthorized activity involved data belonging to millions of individuals registered in the national population database.
Authorities continue evaluating the breach’s access pathway, affected records, and the safeguards related to private-company use of the CPR system. Separately, Datatilsynet is reviewing privacy implications stemming from the incident. The CPR administration has suspended the company’s access and implemented security measures, while officials proceed with a broader review of the registry. As of Oct. 7, no public disclosures have been made regarding the identity of the attackers, the private company involved, or the specific method used to exploit the authorized access.