Denmark investigates major breach affecting 8.8 million CPR records

Denmark investigates major breach affecting 8.8 million CPR records

Danish authorities are investigating a major security incident after unauthorised individuals accessed personal information relating to approximately 8.8 million people through a private company’s legitimate access to the country’s Central Person Register.

Denmark’s Central Person Register (CPR) Administration is investigating a serious security incident after unauthorised individuals gained access to personal information relating to approximately 8.8 million people registered in the system.

The compromised information included names, addresses, CPR numbers and other information relating to people registered in the CPR system, including living people, individuals who have moved abroad and those who are deceased.

The CPR system currently contains information relating to approximately 11 million registered people, meaning the incident potentially affects a substantial proportion of the records held within the system.

However, the investigation carried out so far indicates the unauthorised access did not include the names and addresses of people who have registered for name and address protection.

According to the CPR Administration, the incident involved the misuse of a private Danish company’s legitimate access to search for information held within the CPR system.

Under Danish legislation, private companies with a legitimate interest can be granted access to certain CPR information concerning defined groups of individuals. Companies must identify those individuals in advance using information such as their CPR number, date of birth and name, or their name and address.

Companies accessing the information must also be entitled to receive it under the General Data Protection Regulation and the Danish Data Protection Act.

The CPR Administration said the unauthorised individuals exploited one company’s legitimate access to the system and were able to obtain information that private companies are permitted to access.

Following the discovery of the incident, the company’s access to the CPR system was terminated.

The CPR Administration first became aware of irregular activity within the system on the evening of October 2. Investigations conducted over the following weekend established that unauthorised individuals had accessed information during September.

The incident has been reported to the Danish Data Protection Agency, while police are investigating the case in co-operation with other relevant authorities.

Officials are continuing to establish exactly how the incident occurred and the full extent of the unauthorised activity.

Christina Egelund, Minister for Higher Education and Science and Minister for Digitalisation, said: “It is a deeply serious incident, which is why I have also informed the Danish Parliament’s Business and Digital Affairs Committee. Together with all relevant authorities, we are working to establish the full extent of the incident. We have already initiated measures relating to the CPR system that are intended to prevent similar incidents. In addition, I have requested a thorough security review of the CPR system.

“I would urge all citizens to remain vigilant now and in the coming period and to consult sikkerdigital.dk.”

Authorities have already introduced measures relating to the CPR system designed to prevent similar unauthorised access from occurring.

A comprehensive security review of the system will also be carried out, with its findings expected to help determine whether further security measures need to be introduced.

The authorities stressed that the investigation remains at an early stage and that further examination of the incident could result in details about its scale or circumstances being revised.

At present, investigators have not identified who was responsible for accessing the information.

In response to the incident, Danish authorities have also warned citizens to be particularly alert to potential fraud and social engineering attempts that could exploit the compromised personal information.

Citizens have been advised never to provide passwords or other confidential information following unsolicited telephone calls, emails or similar approaches, even when the person making contact appears to know their name, address or CPR number.

The government is directing people seeking further information and advice to Denmark’s digital security information service, Sikkerdigital.

Additional guidance is being made available through the country’s Cyberhotline for digital security, which has extended its opening hours following the incident.

The CPR Administration and other relevant authorities are continuing their investigation into the circumstances surrounding the unauthorised access, including how the company’s legitimate access was misused.

The investigation will also seek to establish who was behind the activity and whether further action is required to protect information held within the CPR system.

The Danish government said the security review and investigation will provide the basis for deciding whether additional measures need to be implemented following one of the most extensive incidents involving access to information held within the country’s central population register.

The investigation remains at an early stage and Danish authorities have not disclosed the precise method used to obtain the unauthorised access or identified those responsible. The following comments represent the experts’ assessments based on information currently available.

Dray Agha, Senior Manager of Security Operations at Huntress

This incident demonstrates the inherent risk of highly centralised national databases when private companies are granted direct access to sensitive records. A compromised account at a single supplier can bypass an organisation’s core security controls and turn a legitimate connection into a massive data exposure. To defend against this threat, governments and businesses must also strictly limit what external partners are allowed to view. They must also monitor these systems continuously to detect unusual search patterns before millions of records are extracted.

Jamie Akhtar, CEO and Co-founder of CyberSmart

The breach of Denmark’s Central Person Register has exposed names, addresses and personal identification numbers belonging to around 8.8 million people, including those who have died or emigrated. According to reports, attackers exploited a private company’s legitimate access to the register. This highlights how access granted to third parties can become a route to sensitive information, with exposed personal details potentially helping criminals impersonate individuals or make scams more convincing.

Anyone affected should remain alert to phishing emails, text messages and calls, particularly those claiming to come from banks or public authorities. Knowing your name, address or identification number does not make a caller trustworthy. Customers must verify requests through an official website or a known telephone number, check accounts for unusual activity and report suspected fraud promptly. Change any passwords known or suspected to be compromised, including wherever they have been reused, and enable multi-factor authentication (MFA), or passkeys where available. Changing a password cannot undo the exposure of personal information, but it can help protect an affected account.

For the future, individuals should use unique passwords stored in a password manager, keep devices updated and make secure authentication a habit. Organisations must take responsibility for protecting the information entrusted to them. Collect and retain only what they need, restrict access to what each user or supplier requires, and monitor for unusual activity. Regular supplier security reviews, staff training and rehearsed incident response plans should support these controls. This incident is a reminder that a trusted supplier’s access needs the same scrutiny as an organisation’s own systems.

Nathan Davies-Webb, Principal Consultant Acumen Cyber 

The Danish Ministry of Research, Education and Digitalisation has released a statement regarding a cybersecurity incident affecting a large volume of data subjects. Approximately 8.8 million people are impacted, which represents roughly 80% of the ~11 million individuals registered in the system. 

The exposed data includes names, addresses and CPR numbers, along with a person’s status (living, emigrated, deceased), which provides a helpful basis for social engineering and ID fraud. There is limited information on how the data was accessed, although the statement confirms the access came from abuse of a private Danish company’s legitimate access to the system. No attribution has been made public at this stage, so further detail is speculative. 

This breach also highlights the importance of assessing risk correctly and going beyond identifying systems that serve a critical function. Many cybersecurity frameworks recommend quantifying data in terms of value and volume, and identifying scope for abuse, which must include third parties. Centralised systems like this should be treated with the utmost importance. That can include mandating stronger authentication, shorter sessions, rate limiting data requests and creating a baseline of normal behaviour to support monitoring. 

Overall, it is very positive to see the current transparency, especially the extended hours on the digital security hotline. These behaviours can indicate that response plans are in place and being followed.

Browse our latest issue

Intelligent Gov.tech Issue 01

View Magazine Archive