Skip to content

Denmark data breach exposes CPR records of 8.8 mn people

Denmark data breach exposes CPR records of 8.8 mn people

Denmark has reported a major data breach involving its Central Population Register, with personal information on about 8.8 mn registered people accessed without authorisation. The exposed data included names, addresses and CPR numbers, Denmark’s personal identification numbers used across public and private services, Ministry of Research, Education and Digitalisation stated.

The affected records include people currently living in Denmark, former residents who moved abroad and deceased individuals. Denmark has a population of roughly 6 mn, while the CPR system contains records on around 11 mn people.

The unauthorised access did not result from a direct breach of the central registry. According to the Ministry of Higher Education, Science and Digitalisation, unidentified individuals used a private Danish company’s legitimate access to search information held in the CPR system. The CPR administration has since stopped the company’s access.

Officials discovered irregular activity on the evening of Friday, Oct. 2, after unusual behaviour had occurred in the system during September. Over the weekend, investigators established that information covering approximately 8.8 mn registered people had been accessed.

People registered with name and address protection were treated differently. The government’s initial review found that the unauthorised access did not include their protected names and addresses.

Denmark launches investigation into CPR breach

Police are investigating the incident with other relevant authorities, while the CPR administration has reported the breach to Denmark’s Data Protection Agency. Investigators have not identified who was responsible, and officials said the inquiry remains at an early stage.

Digital Affairs Minister Christina Egelund described the breach as an extremely serious incident and said parliament’s Business and Digitalisation Committee had been informed. Authorities are working to establish the full sequence of events and the final scope of the exposure.

Together with all the relevant authorities, we are in the process of mapping out the full extent of the incident. We also ordered a security review of the CPR system following the breach.

Digital Affairs Minister Christina Egelund

The government said measures have already been introduced to prevent a similar incident. Further action will depend on the findings of the security review and the continuing investigation into how the company’s authorised access was misused.

Authorities warn about phishing risk

Danish authorities urged residents to remain alert to phishing and other attempts to exploit the exposed information. People were advised not to provide passwords or confidential information in response to phone calls, emails or similar requests, even when the sender or caller already knows their name, address or CPR number.

The government directed residents seeking assistance to its digital security service and Cyberhotline. The hotline extended its opening hours following disclosure of the breach as authorities continued examining the incident.

Private companies with a legitimate interest are permitted under Danish law to obtain specified CPR information about identified individuals, subject to data protection requirements. In this case, the unauthorised parties used access held legally by a private Danish company, rather than obtaining unrestricted access to the entire CPR system.

The exact sequence remains under investigation. Officials said further work could alter some of the initial findings as police, the CPR administration and other authorities establish how the access occurred and who was responsible.