Denmark’s government admitted on Monday that hackers broke into the country’s central population database and walked off with the personal data of about 8.8 million people.
The breach hit the Central Person Register, known as CPR, Denmark’s national ID database. Stolen data includes names, home addresses, and CPR numbers — the unique 10-digit personal identification numbers every Dane uses to pay taxes, see a doctor, and deal with banks.
Officials say the unauthorized access happened in September 2026 and wasn’t spotted until Friday, October 2. By the time the scope was clear over the weekend, the Danish government had what TechCrunch calls the biggest data breach in the country’s history.
That’s nearly everyone the registry has ever recorded.
How the hackers got in
There was no zero-day exploit and no exotic malware. Instead, the attackers went through a private Danish company that had legitimate permission to search the CPR system — a credential companies use to verify people’s information with the government.
According to the Danish government, the intruders abused that company’s lawful access to run unauthorized searches. BleepingComputer’s reporting adds a technical detail from the Danish Data Protection Agency: the attack involved brute-forcing, systematically enumerating valid CPR numbers and then pulling the data attached to each entry.
Once the scale became clear, authorities blocked the company’s access to the registry. Police have opened an investigation, and the government says it’s too early to say who was behind the attack. The administration has not named the company whose access was misused.
Digital Affairs Minister Christina Egelund ordered a comprehensive security review of the CPR system and told Parliament’s Business and Digitalization Committee about the incident. “This is an extremely serious incident,” Egelund said in the government’s statement. “Together with all the relevant authorities, we are in the process of mapping out the full extent of the incident.”
She also warned Danes to stay alert for suspicious calls and emails — the standard first step before the phishing campaigns that usually follow a leak like this.
Why 8.8 million in a country of 6 million
The number looks odd until you know how the registry works. Denmark has about 6 million residents, but the CPR system holds records on roughly 11 million people. It keeps entries for decades, including people who have died and Danes who have emigrated.
So the breach reached back in time: the 8.8 million affected include the living, the deceased, and former residents now living abroad — roughly 80 percent of every record the registry holds.
One group was spared. People registered in the system for name and address protection — typically those with personal safety concerns — were not exposed, the government said.
What the Denmark data breach means for digital ID systems
This is the part that should make every government-run ID database nervous. CPR numbers can’t be reissued the way a password can. They follow you from birth certificates to bank accounts, and they’re the single key that unlocks identity verification across Denmark’s famously digitized public sector.
That permanence is exactly why breaches like this one keep happening at national scale. TechCrunch drew the obvious parallels: a 2016 breach that exposed millions of Turkish citizens’ records, and the repeated leaks of personal data from India’s Aadhaar national ID database.
For US readers, the lesson travels. Social Security numbers, Aadhaar numbers, CPR numbers — once they’re copied out of a central database, they can’t be put back. The damage compounds for years through identity theft and fraud, and the victims are rarely the ones who get to decide how carefully their data was guarded.
Egelund’s government hasn’t said what the comprehensive security review will change, or whether companies with CPR access will face new restrictions. The police investigation is still in its earliest stages. But the brute-forcing detail matters: enumerating 8.8 million records takes time and volume, which raises the question of why anomaly detection didn’t flag the activity before October 2.
FAQ
What happened in the Denmark data breach?
Hackers gained unauthorized access to Denmark’s Central Person Register (CPR), the national population database, and stole names, addresses, and CPR national ID numbers of about 8.8 million registered people. The Danish government disclosed the breach on October 5, 2026; the attack happened in September and was discovered October 2.
What is the CPR number that was exposed?
The CPR number is Denmark’s unique 10-digit personal identification number, assigned to every resident. It is used to identify people when dealing with government agencies, banks, and healthcare providers, which makes its exposure a serious identity-theft risk.
How did hackers get into Denmark’s national registry?
The attackers misused a private Danish company’s legitimate access to search the CPR system, according to the Danish government. The Danish Data Protection Agency said the attack involved brute-forcing to enumerate valid CPR numbers and then extracting the data attached to each entry.
Who is at risk from the Denmark CPR breach?
About 8.8 million registered people, including Danes living abroad and the deceased, since the registry holds roughly 11 million records against a current population of about 6 million. People registered for name and address protection were not exposed, officials said.
Sources: TechCrunch, BleepingComputer, Agence France-Presse (via The Straits Times and Leadership), The Edge Singapore.
