Denmark CPR register breach exposes data of 8.8 million people
Denmark is investigating a breach of its Central Person Register (CPR) that affects roughly 8.8 million people, according to The Record, which cites a government statement issued Monday. The Denmark data breach reportedly exposed names, addresses and CPR numbers, the ten-digit identifiers used across Danish healthcare, banking and government services. Officials have not said who is responsible.
What we know about the Denmark data breach
- Officials say they first detected irregular activity on the CPR system on Friday.
- Weekend investigations concluded that the breach took place during September, according to The Record.
- Denmark’s Data Protection Agency says it was notified on Sunday. It described the activity as a very large number of automated searches aimed at identifying valid CPR numbers.
- The attackers reportedly abused the legitimate access of an unnamed domestic company to reach the register.
- Research, education and digitalisation minister Christina Egelund called the incident “deeply serious” and ordered a broad security review of the system.
- The national digital security hotline will run extended hours, 8 a.m. to midnight, for the next few days.
Who is affected
The register holds records on around 11 million people, including current residents, people who have moved abroad and people who have died. About 8.8 million of those records are reported as exposed. Denmark’s current population is just over six million, so many of those affected no longer live in the country or are deceased.
The data involved is names, addresses and CPR numbers. The sources do not say that health, financial or other records were taken. Because CPR numbers begin with the holder’s date of birth and are meant to last a lifetime, the risk to those affected could persist for years, as The Record notes.
What has not been confirmed
- The identity or motive of the perpetrators has not been disclosed.
- The company whose access was used has not been named, and it is not stated how that access was compromised.
- Whether any data has been published, sold or otherwise misused has not been disclosed.
- The exact number of records retrieved versus the number of people affected has not been detailed beyond the 8.8 million figure.
Why this matters
Analysis, not reported fact. The reported method, high-volume automated lookups through a trusted third party’s access, is a supply-chain and access-abuse pattern rather than a break-in at the register itself. Names, addresses and an identifier that cannot be changed make convincing material for phishing, identity-verification fraud and social engineering. Organisations that use CPR numbers as a knowledge-based check should assume that factor is weakened.
Commentators quoted by The Record, including Huntress’s Dray Agha, point to the inherent risk of centralised national databases that private companies can reach directly.
What to do
- Individuals in Denmark: follow guidance from the Danish authorities and use the extended-hours digital security hotline if you have questions. Treat unexpected calls, texts or emails that cite your CPR number or address as suspicious.
- Organisations that verify identity with CPR numbers: stop treating a CPR number alone as proof of identity and add a second factor or out-of-band check.
- Companies with direct register access: review API and account permissions, rate limits and alerting for bulk or sequential lookups, since the reported activity involved automated searches for valid numbers.
- Security teams: hunt for unusual query volumes from third-party or service accounts against sensitive registries, and for authentication attempts that use leaked-style personal data.
- Customer-facing teams: brief staff and users on likely follow-on phishing and fraud attempts.
