Denmark has confirmed a major data breach involving its Central Population Register, known as CPR, after unauthorized parties accessed personal records belonging to about 8.8 million people. The exposed information includes names, addresses, and CPR numbers, according to an official statement published on October 5, 2026.
The figure exceeds Denmark’s population of roughly six million because the register also holds records of people who have moved abroad and those who have died. Officials said the CPR system currently contains approximately 11 million registered people, meaning the incident affected a large share of its records.
…
The attackers misused a private Danish company’s lawful access to search the CPR system during September. Authorities have not described how the unauthorized parties obtained or used that access, leaving the initial entry method unknown.
The confirmed route is important: this was misuse of an approved company connection, not a publicly confirmed software flaw in the register. The ministry has not disclosed the company’s name, linked the incident to a known threat group, or identified a specific vulnerability.
…
Research, Education and Digitalization Minister Christina Egelund described the incident as deeply serious. She informed Parliament’s Business and Digitalization Committee and requested a thorough security review of CPR. Officials said preventive measures had already started, without detailing their technical scope.
…
Names, addresses, and national identification numbers can make fraudulent messages and calls appear convincing. Cybersecurity News’ coverage of the Pentagon data breach similarly highlights the risks when personal records include identity numbers, while its phishing prevention guidance explains common warning signs.
…



Having used the system some time ago, I’m not too worried. It only shows the name and latest address. Basically like the white pages but with a soc.sec.ID instead of the phone number.
It lacks info on a lot of people, because some people aren’t too good at reporting when they move, and some are hidden for legal reasons.
The most dangerous thing would be if the data is sold to stalkers, because it does have more addresses than the white pages.
The soc.sec.no. includes birthday and gender, so it can also be used for targeting scams.
Anyway, it’s not like this data wasn’t already available in one way or another. The breach just made it easier for whoever did it.
Ah, so the equivalent of the Swedish ratsit/eniro/mrkoll etc…