COPENHAGEN, DENMARK / RankWire.AI / – Danish authorities are investigating unauthorized access to personal data in the country’s Central Person Register, known as CPR. The incident affected records linked to about 8.8 million people. Accessed information included names, addresses, CPR identification numbers and other registered details. Officials said the attackers used credentials connected to a private Danish company with legitimate permission to search the national population system. Authorities have not named that company.

The CPR administration detected unusual activity on the evening of Oct. 2 after a series of searches during September. Officials reviewed the activity over the following weekend and established the scale of the access. Denmark’s CPR database contains about 11 million records in total. The system covers current residents, people who have moved abroad and deceased individuals. Officials said the searches remained within categories of information available through authorized CPR services.
Authorities have not identified the people responsible for the unauthorized searches. The CPR administration ended the company’s access after finding the suspicious activity. Danish police and other authorities are examining how the incident occurred and which records the searches reached. Officials also reviewed information covered by Denmark’s name and address protection scheme. They found that protected names and addresses under that program did not form part of the exposed information.
Data regulator reviews automated CPR searches
Datatilsynet, Denmark’s data protection regulator, received the incident notification on Oct. 4. The regulator said a very large number of automated searches had taken place against the CPR system. According to the notification, the searches aimed to identify valid CPR numbers. Datatilsynet is examining how unauthorized parties gained access and what personal information they obtained. Its review also covers responsibility for processing the affected data under Danish data protection rules.
Research, Education and Digitalisation Minister Christina Egelund described the incident as deeply serious and informed parliament’s Business and Digital Affairs Committee. She ordered a broad security review covering the CPR system and its access controls. The government has also started measures designed to reduce the risk of similar incidents. Authorities continue mapping the sequence of events and reviewing safeguards used by private organizations that receive approved access to CPR information.
Public warned about possible fraud attempts
Danish authorities urged residents to stay alert for fraudulent calls, emails and messages that could contain exposed personal details. Officials warned people not to disclose passwords or confidential information because a caller already knows their name, address or CPR number. The government directed residents toward official digital security guidance and Denmark’s cyber hotline. Authorities have not confirmed that attackers used the accessed information for fraud, identity theft or other criminal activity beyond the unauthorized searches.
Investigators continue examining the access route, affected records and security controls surrounding private use of the CPR system. Officials have not disclosed the company’s identity or the exact method used to misuse its authorized access. Authorities also have not publicly identified those behind the searches. As of Oct. 7, the CPR administration, police and regulators were continuing separate reviews of the incident while Denmark assessed security around its national population register.
