# Massive Data Breach Exposes 8.8 Million Records in Denmark’s National Population Register
Denmark’s Central Person Register (CPR), the country’s national population database, has been hit by a significant data breach. Unauthorized parties have gained access to the names, addresses, and personal identification numbers of approximately 8.8 million people, including both living residents and deceased individuals. The breach was carried out by exploiting the legitimate access rights of a small Danish private company, which has since had its credentials revoked.
The unauthorized access persisted for roughly ten days during September. An employee at the register’s administration noticed unusual activity on October 2nd, and the scope of the breach was confirmed over the weekend. Authorities have since reported the incident to Datatilsynet, the national data protection authority, and police have launched a formal investigation. The exact identity of the unauthorized parties, how they initially compromised the company’s systems, and whether the stolen data has been retained or misused remain unknown.
The compromised data represents nearly the entirety of the register, which holds records for about 11 million people. The CPR system has documented every individual who has lived or currently lives in Denmark since 1968. Fortunately, the breach did not extend to the names and addresses of people who have opted for name-and-address protection, a status that legally prevents private companies from viewing such details. However, it is still unclear whether the CPR numbers themselves of these protected individuals were also targeted.
Under current regulations, private companies can legally request data from the register for people they have already identified on an individual basis. A CPR number is often enough to trigger this lookup. The format of the CPR number—consisting of ten digits where the first six represent the date of birth—may have played a role in how the attackers systematically identified valid records, though this has not been confirmed.
In response to the breach, officials are advising the public to take immediate steps to protect themselves. Citizens are urged to remain highly vigilant against unexpected text messages, calls, and emails that contain personal details, as attackers may use the stolen information to craft convincing phishing attempts. The public is also warned never to share authentication codes, passwords, or financial details over the phone or via email. Additionally, individuals are encouraged to set up a credit warning on the national digital portal, which acts as a flag for lenders to exercise heightened caution before extending credit in a person’s name.
### Frequently Asked Questions (FAQ)
**What is a CPR number?**
A CPR number is the national personal identification number used in Denmark. It consists of ten digits: the first six represent the date of birth, and the final four are serial digits, with the last digit being even for women and odd for men.
**Can I get a new CPR number if mine was compromised?**
Yes, legislation exists that allows for a CPR number to be reassigned in special cases where a person’s number has been misused. However, authorities have not yet confirmed whether large-scale re-issuance will be necessary for those affected by this breach.
**What is a credit warning?**
A credit warning is a marker placed within the national register that signals companies to take extra care when verifying identity before approving loans or credit in a person’s name. It acts as a protective signal, though it may temporarily make loan applications more difficult to approve.
**Why were so many records accessed through one company?**
Investigators are currently looking into how the attackers managed to use a single company’s access rights to query records covering roughly four out of every five people in the national register. It remains unclear how the attackers bypassed the company’s internal security protocols or the exact scope of the automated lookups performed.
### Conclusion
This incident underscores the critical vulnerabilities that exist within centralized digital identity systems, particularly when third-party access is involved. As the data protection authority and law enforcement continue their investigations to determine accountability, the government has initiated a comprehensive security review of the national register. The coming weeks will be vital in understanding the full scope of the breach and implementing the necessary regulatory and technical safeguards to prevent similar incidents in the future. Thank you for reading



