Denmark CPR Breach Hits 8.8M Citizens

Original: Denmark Data Breach Exposes 8.8M People's Personal Data

Why This Matters

Near-total national ID exposure sets a high-stakes precedent for population registries.

Denmark's Central Person Register (CPR) confirmed unauthorized access to names, addresses, and CPR numbers of approximately 8.8 million registered citizens after a Danish company's legitimate system access was misused.

Denmark's CPR administration announced on October 5, 2026 that an unknown party exploited a Danish company's authorized access to the CPR system to extract personal data on roughly 8.8 million people — effectively the entire Danish population. Stolen data includes names, home addresses, and CPR numbers (Denmark's national ID numbers). The CPR administration confirmed that individuals who had registered name and address protection were not affected by the breach. Access for the implicated company has been revoked. CPR administrators are working alongside technical specialists and authorities to reconstruct the full sequence of events. A formal report has been filed with the Danish Data Protection Authority (Datatilsynet), and police are conducting a criminal investigation in cooperation with relevant agencies. Further details are available on the website of the Ministry of Research, Education and Digitalisation.

Source

cpr.dk — Read original →