Skip to main content

Morning Overview

Hackers took names, addresses and ID numbers for 8.8 million people from Denmark’s national register

Christina Egelund, Denmark’s Minister of Research, Education and Digitalisation, called it “a deeply serious incident” and said she had informed Parliament’s Business and Digitalisation Committee. The incident was a breach of the Central Population Register, known as the CPR, announced on October 5, 2026: records covering about 8.8 million people, roughly 80% of the 11 million in the register, were pulled out by people who had no right to hold them. The total reaches current residents, Danes living abroad and deceased people alike.

What was taken is the identity layer that Danish institutions use to recognize a person: name, address and the personal CPR number, with some reports adding more.

A private company’s access, misused

BleepingComputer reports that the attackers misused a private Danish company’s legitimate system access, using brute-force attempts to enumerate valid CPR numbers and extract the data attached to them. Help Net Security describes the same pattern from the Danish announcement: the requests stayed within the data-retrieval parameters the company was authorized to use, so the access itself was legitimate even though the use of it was not.

Why a private company could query the register at all is a matter of law. IBTimes Singapore, citing CPR administration officials, says the attackers exploited “a Danish company’s legal access to search for information in the CPR system,” and that private companies can lawfully reach certain CPR information under Section 38 of Denmark’s Civil Registration Act. The authorities in that account learned of the unauthorized access on the evening of October 2, after irregular behavior had been detected in September, and only then established that extensive personal information had been taken.

The difference between that account and the word “hackers” is one of degree, not of fact. No source describes a break into the register’s servers; each describes searches run through an authorized channel, which the sources describe as misuse of that access. In the IBTimes account, the government ended the company’s access, reported the case to the Data Protection Authority and opened a police investigation.

Denmark’s account is that the company’s access to the register was revoked immediately and that police opened an investigation alongside the relevant authorities. Help Net Security says no suspect had been identified when the announcement was made.

The timeline comes in slightly different versions. BleepingComputer puts the breach in September 2026, the discovery by the CPR administration on October 2 and the public announcement on October 5. Recordere, quoting the Research, Education and Digitalisation Ministry, says irregular activity in the system was detected during September and that the full scale became apparent over the following weekend. Help Net Security gives the discovery as October 2 to 4.

Fields in the extract, and who is covered

The Danish government’s own cyber-safety site, sikkerdigital.dk, states that unauthorized parties obtained “navne og adresser samt CPR-numre,” meaning names and addresses together with CPR numbers. BleepingComputer’s list is longer: names, addresses, dates of birth, marital status and the unique CPR identification numbers. Help Net Security and Recordere give the shorter list, so the minimum confirmed across the reports is the name, the address and the number, and the longer list rests on one outlet.

Help Net Security describes the numbers as 10-digit CPR numbers and says people who had registered name and address protection were not included in the extract. BleepingComputer says the affected records include residents, expatriates and deceased individuals.

The register itself is long-established. The CPR office, which runs the Central Personal Register as a department of the ministry responsible for digital affairs, dates the system to 1968. A system that old, and that central, is the reason the 8.8 million figure is read as most of the country rather than as a sample.

Official guidance and the investigation

The government’s advice is aimed at fraud rather than at the data already out. Egelund urged the public, according to Recordere, to be extra vigilant about text messages, calls and emails in which the sender uses personal details about the recipient. Sikkerdigital.dk tells people not to let a caller pressure them into acting hastily, to hang up and phone the organization’s published main number to check the sender, and it directs businesses to the same verification habits. A cyber hotline is available through the site.

BleepingComputer’s version of the official warning is the sharpest: never disclose passwords or confidential information in response to calls or emails, even if the sender already knows the person’s name, address and CPR number. Recordere adds specifics from the ministry’s guidance: avoid links in unexpected messages, never share MitID credentials or payment details, and consider setting up a credit alert through borger.dk.

The Danish Data Protection Agency has opened a case, Help Net Security reports, and the CPR administration has begun a security review of the system to prevent a repeat. As of the announcement, authorities were still mapping the full incident, and the 8.8 million figure, about 80% of an 11-million-record register, was the count Denmark had published.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview


Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.