COPENHAGEN, DENMARK / RankWire.AI / – Danish authorities are investigating unauthorized access to personal data in the country’s Central Person Register, known as CPR. The incident affected records linked to about 8.8 million people. Accessed information included names, addresses, CPR identification numbers and other registered details. Officials said the attackers used credentials connected to a private Danish company with legitimate permission to search the national population system. Authorities have not named that company.

The CPR administration detected unusual activity on the evening of Oct. 2 after a series of searches during September. Officials reviewed the activity over the following weekend and established the scale of the access. Denmark’s CPR database contains about 11 million records in total. The system covers current residents, people who have moved abroad and deceased individuals. Officials said the searches remained within categories of information available through authorized CPR services.
Authorities have not identified the individuals responsible for the unauthorized searches. The CPR administration revoked the company’s access once suspicious activity was discovered. Danish police and other authorities are now investigating how the breach occurred and which records were accessed. Officials also examined data protected under Denmark’s name and address protection scheme, concluding that names and addresses under this scheme were not part of the compromised information.
Data Protection Agency Analyzes Automated CPR Search Activities
Datatilsynet, Denmark’s data protection authority, received the incident report on Oct. 4. The regulator indicated that a substantial number of automated searches had targeted the CPR system. According to the report, these searches were conducted to verify valid CPR numbers. Datatilsynet is investigating how unauthorized entities gained access and what personal data was retrieved. The review also covers the responsibilities related to processing the impacted data under Danish privacy laws.
Research, Education and Digitalisation Minister Christina Egelund characterized the breach as highly serious and briefed parliament’s Business and Digital Affairs Committee. She ordered a comprehensive security assessment of the CPR system and its access protocols. The government has initiated measures to mitigate future risks, with authorities continuing to trace the sequence of events and assess the safeguards private organizations use for authorized CPR data access.
Public Advised to Remain Vigilant Against Fraud
Danish officials advised residents to stay alert for potential scam calls, emails, and messages that could leverage exposed personal information. Citizens were cautioned not to share passwords or sensitive data if contacted by someone who already knows their name, address, or CPR number. The government recommended consulting official digital security resources and Denmark’s cyber hotline. Authorities have not confirmed whether the accessed information has been exploited for fraud, identity theft, or other criminal acts beyond the unauthorized searches.
Investigations into the breach continue, focusing on the method of access, the records involved, and the security measures surrounding private use of the CPR database. The identity of the company involved and the specific technique used to misuse its authorized access have not been publicly disclosed. Authorities also have not revealed the individuals responsible for the searches. As of Oct. 7, the CPR administration, police, and regulators are conducting separate reviews of the incident, while Denmark evaluates the security protocols for its national population register.
