Denmark CPR Breach Hits 8.8M Citizens
Original: Denmark Data Breach Exposes 8.8M People's Personal Data
Why This Matters
Near-total national ID exposure sets a high-stakes precedent for population registries.
Denmark's Central Person Register (CPR) confirmed unauthorized access to names, addresses, and CPR numbers of approximately 8.8 million registered citizens after a Danish company's legitimate system access was misused.
Denmark's CPR administration announced on October 5, 2026 that an unknown party exploited a Danish company's authorized access to the CPR system to extract personal data on roughly 8.8 million people — effectively the entire Danish population. Stolen data includes names, home addresses, and CPR numbers (Denmark's national ID numbers). The CPR administration confirmed that individuals who had registered name and address protection were not affected by the breach. Access for the implicated company has been revoked. CPR administrators are working alongside technical specialists and authorities to reconstruct the full sequence of events. A formal report has been filed with the Danish Data Protection Authority (Datatilsynet), and police are conducting a criminal investigation in cooperation with relevant agencies. Further details are available on the website of the Ministry of Research, Education and Digitalisation.