Denmark's government disclosed that its Central Person Register (CPR) was compromised and that most of its contents were stolen, in what is believed to be the country's largest data breach. Hackers obtained names, addresses and CPR numbers — ten-digit identifiers beginning with a person's date of birth, roughly comparable to US Social Security numbers — covering about 8.8 million people. The register holds data on roughly 11 million people, including current residents, Danes who moved abroad and the deceased; Denmark's current population is just over six million.

The intrusion did not require breaking into the register directly. According to the government, the attackers 'abused a Danish company's lawful access to search for information in the CPR system'. Several Danish companies are authorised to query CPR data to verify identities with the state. Denmark's Data Protection Agency, notified on Sunday, described a very large number of automated searches aimed at identifying valid CPR numbers — a sign that the data was systematically harvested rather than opportunistically copied.

Christina Egelund, the minister for research, education and digitalisation, called it 'a deeply serious incident' and said she had ordered a broad security review of the system. The national digital-security hotline extended its opening hours from 8 a.m. to midnight in the days after the disclosure. Officials said irregular activity was first detected on Friday, October 2, and that weekend investigations placed the actual breach in September. The government has not publicly attributed the attack.

Because CPR numbers are used for healthcare, banking and public services and are intended to last a lifetime, the exposure has an unusually long tail. Security analysts described the case as a textbook failure of trust concentration. 'This incident demonstrates the inherent risk of highly centralized national databases when private companies are granted direct access to sensitive records,' said Dray Agha, senior manager of security operations at Huntress. 'A compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure.'

The breach is the most serious to hit the CPR system since 2015, when two unencrypted CDs containing data on more than five million people were mistakenly delivered to the Chinese Visa Application Centre in Copenhagen; authorities said at the time there was no evidence the data had been copied. Population-scale registry breaches have also struck Turkey in 2016, India's Aadhaar database and Argentina in 2021.