COPENHAGEN, DENMARK / RankWire.AI / – The Danish Data Protection Agency, Datatilsynet, is now examining a significant security breach involving the country’s Central Person Register. Unauthorized access to personal data of approximately 8.8 million individuals has been confirmed. The compromised information comprised names, addresses, CPR numbers, and related records. Officials explained that the attackers utilized legitimate access granted to a private Danish company to search the CPR system. As part of the investigation, the CPR administration has suspended the company’s access while authorities look into how the breach occurred.

The incident was detected by the CPR administration on the evening of Oct. 2 after unusual search activity was noticed during September. Over the weekend, authorities reviewed the activity, confirming the extent of the unauthorized data retrieval. The Central Person Register includes around 11 million records, covering current residents, individuals who have moved abroad, and deceased persons. Officials emphasized that the searches remained within the bounds of information that private companies are permitted to access via authorized CPR services.
No suspects have been identified at this stage, and the private company involved has not been named by Danish officials. The CPR administration has reported the breach to Datatilsynet and police are conducting investigations alongside other authorities. The government stated that its review found no exposure of names and addresses belonging to individuals registered under Denmark’s name and address protection scheme.
Regulator looks into automated searches within CPR system
Datatilsynet announced it received the breach report from the CPR register on Oct. 4. The regulator highlighted that the incident involved a very high volume of automated searches targeting the CPR system. According to the notification, these searches aimed to verify valid CPR numbers. Datatilsynet is now investigating how the breach took place, how access was obtained, and which parties are responsible for processing the data involved. The agency assured that further details will be shared once sufficient information is available.
Research, Education and Digitalisation Minister Christina Egelund described the incident as deeply serious and briefed Denmark’s parliament Business and Digital Affairs Committee. She has also ordered a comprehensive security review of the CPR system. The government has initiated measures aimed at preventing similar breaches in the future, while the CPR administration continues to reconstruct the sequence of events. Authorities noted that the investigation remains in its early stages, and technical assessments may clarify additional details.
Public advised to stay vigilant against scam attempts
Danish officials urged residents to be cautious of fraudulent calls, emails, and other messages that might leverage exposed personal information. Officials emphasized that individuals should never share passwords or confidential data just because a caller or sender appears to know their name, address, or CPR number. The government directed citizens to official digital security resources and Denmark’s cyber hotline. This warning came after confirmation that the unauthorized activity involved data belonging to millions of registered people in the national population registry.
Authorities are continuing to evaluate the route of access, the affected records, and the safeguards around private-sector use of the CPR system. Separately, Datatilsynet is reviewing the data protection implications of the incident. The CPR administration has suspended the company’s access and implemented security measures, while officials are conducting a broader review of the registry. As of Oct. 7, authorities had not publicly identified the perpetrators, disclosed the company’s name, or confirmed the specific method used to abuse its authorized access.