Denmark’s central population register (CPR) was the target of a large-scale data access event: unauthorized parties used a private company’s legitimate access rights to query the register and, according to official statements, obtained names, addresses and personal identification numbers for roughly 8.8 million people. The activity lasted about ten days in September and was discovered by the register’s administration on October 2; the company account was suspended and the case reported to Datatilsynet while police investigate. At this stage officials say the access remained within the type of data companies are allowed to receive, but many questions about how it happened and whether the data has been further copied or misused remain unanswered.
What was exposed
The ministry’s preliminary figure — about 8.8 million records — covers living residents, people who have moved abroad, the deceased and others listed in the register. The CPR holds roughly 11 million entries in total, so this incident potentially affected about four in five recorded persons. Officials say the access did not include names and addresses for people who have formal name-and-address protection, though the ministry did not clarify whether those individuals’ CPR numbers themselves were reached. The notification to Datatilsynet describes mass automated lookups used to identify valid personal numbers, but it does not confirm the exact method attackers used or whether data was exfiltrated after the queries.
How access may have been possible
Under the 2023 CPR Act, private companies can request register data for people they have already identified one-by-one; a CPR number alone is sufficient to retrieve a record in many cases. A CPR number is ten digits long (six for date of birth plus four serial digits), which mathematically limits possibilities per birth date — and Datatilsynet’s notice says lookups were used to identify valid numbers. What remains unclear is how a single company’s account reportedly came to cover such a large portion of the register and why alerts did not trigger sooner. The minister responsible for digitalization, Christina Egelund, has already acknowledged that existing safeguards were not strong enough and has requested a full security review of the register.
Who is affected and what the figure means
The 8.8 million number is provisional and may change after investigation, but it illustrates the scale: current and past residents, people who have emigrated, and the deceased are all represented in the register’s historical coverage since 1968. For most people a CPR number is an identifier used by public and private services; it should not be treated as sole proof of identity. If attackers confirmed CPR numbers at scale, that reconnaissance can feed social engineering, identity fraud, and targeted scams that rely on personal details to convince victims to reveal authentication codes, passwords or banking details.
Immediate steps people should take
Officials and the government point to practical steps every CPR holder can use to reduce harm:
- Be extra alert to unexpected text messages, calls and emails that use personal details. Treat any unusual request for codes, passwords or financial details as suspicious.
- Do not click links in unexpected messages. Instead go to official websites yourself or call the organization’s main number to verify the request.
- Never share MitID credentials, one-time codes, passwords or card details with anyone who contacts you.
- Set up a credit warning (kreditadvarsel) on borger.dk to ask companies that receive CPR data to take extra identity checks before extending credit. A marker can make loan approvals harder until removed and can take a few days to propagate across company systems.
The government’s Cyberhotline (Cyberhotline for digital security) can assist people worried about fraud; the published emergency contact number is +45 33 37 00 37 and it has extended opening hours in the days following the announcement.
Why this matters beyond immediate fraud risk
Beyond scams and loan fraud, large-scale exposure of CPR records raises systemic concerns. Personal identification numbers are a key building block in many administrative and commercial workflows; attackers with confirmed CPR entries can use them to mount phishing campaigns, impersonation attacks, or to enrich other breached datasets. The incident also highlights risk around delegated access: companies given lawful lookup rights must secure those privileges and the systems that use them, because abuse or compromise of a single account can cascade into a national-scale exposure.
What authorities and the register operator are doing
The register administration suspended the company’s access and reported the incident to Datatilsynet, Denmark’s data protection authority. Datatilsynet is examining how the lookups were carried out and who is responsible for handling the personal data. The digitalization minister has requested a full security review of the register and its access controls. It is still too early to say whether affected people will be issued new CPR numbers; the law allows replacing a CPR number in special cases where misuse is proven, but that is not a routine remedy.
Longer-term mitigations to expect
Officials have signaled they will strengthen safeguards around company access to the CPR. Possible measures include tighter authentication for automated queries, stricter limits on bulk lookups, anomaly detection and faster alerting, and clearer contractual and technical requirements for third-party systems that act as intermediaries. For citizens, better education about the limits of what a CPR number can prove and easier, faster ways to place and communicate credit warnings will matter.
What to watch next
The investigation should clarify three things: how attackers gained access to the company account, whether the attackers retained or distributed the data, and the identity or origin of the unauthorized parties. Until Datatilsynet’s review and the police inquiry produce more details, organizations and individuals should treat the situation as an elevated fraud risk and apply the practical steps outlined above.
Atlassian Urges Immediate Patching After Critical Arbitrary File-Access Flaw
Atlassian has released emergency fixes for a critical arbitrary file access vulnerability…
ShinyHunters’ “Rey” Detained in Jordan: What His Cooperation Means for the FBI Probe
A suspected member of the ShinyHunters group who uses the online alias…
Vault Enterprise 2.0: Rethinking LDAP Secrets Management for Enterprise Identity
For security and ops teams, directory credentials have long been a stubborn…
Amazon Drops NDAs as Data Center Backlash Grows
Amazon’s recent move to stop using nondisclosure agreements (NDAs) with government agencies…
Lee Orders Nationwide Security Sweep After Multiple South Korean Bank Breaches
South Korea’s president, Lee Jae Myung, has ordered an urgent and comprehensive…
Critical GitLab AI Gateway Flaw: What Administrators Need to Do Now
GitLab has pushed an urgent set of security updates after disclosing a…
Citrix NetScaler Reboots After Emergency 0-Day Patch: What Teams Need to Know
Citrix released emergency builds to address two actively exploited zero-day vulnerabilities in…
Antino: A Stealthy Backdoor That Hides in Outlook and OneDrive
A new espionage campaign tracked by Cisco Talos has exposed a sophisticated…