Denmark's CPR Registry Breach Exposes Data of 8.8 Million
Threat actors abused a private company's legitimate access to Denmark's Central Population Register, and police have launched an investigation.
Denmark's Central Population Register (CPR) has disclosed a data breach that exposed the personal information of approximately 8.8 million registered individuals. The registry said threat actors misused a private Danish company's legitimate access to the registry system to obtain names, addresses, CPR numbers and other information.
The security incident occurred in September 2026, and the CPR administration became aware of the breach on October 2, 2026.
The Danish Data Protection Agency said the attack involved brute-forcing to enumerate valid CPR numbers and extract related data. The private company's access to the registry has been blocked, and police have launched an investigation. A dedicated cyber hotline has been set up for potentially affected individuals.
The CPR system holds data for 11 million registered citizens, meaning the incident impacted about 80% of that total, according to bleepingcomputer.com.
Quick answers
How many people were affected by the Denmark CPR data breach?
Approximately 8.8 million registered individuals were exposed, out of the 11 million citizens whose data the CPR system holds.
When did the Denmark CPR breach happen?
The security incident occurred in September 2026, and the CPR administration became aware of the breach on October 2, 2026.
What information was exposed in the CPR breach?
Names, addresses, CPR numbers and other information were obtained after threat actors misused a private Danish company's legitimate access to the registry system.