Denmark's central person register — the CPR register that holds the national identity numbers used for everything from healthcare to banking — was breached, and the personal data of roughly 8.8 million registered people was accessed without authorization, the country's digital affairs ministry confirmed on Monday, October 5.

According to the ministry and the CPR administration, the exposed records include names, addresses and CPR numbers. Because the register covers everyone ever issued a Danish personal identification number — including deceased people and Danes living abroad — the 8.8 million figure is larger than Denmark's population of about six million. Bloomberg and Euronews reported the same figure; TechCrunch described the affected group as about eight million people.

Initial findings point to a compromised access route rather than a frontal assault on the registry itself: the intruders appear to have used the legitimate login credentials of a local company, according to DW. The CPR administration said it stopped access once the breach was detected and has since been rotating credentials and tightening monitoring.

The incident ranks among the largest personal-data breaches ever disclosed in Europe, and it hits a national ID layer that cannot simply be reissued the way a password can. CPR numbers anchor Danish identity verification across public services, banks and insurers, so the stolen file is a ready-made toolkit for identity fraud, social engineering and account takeover — damage that will outlast any credential rotation.

It also fits a wider pattern. Attackers are increasingly targeting centralized registries and the third-party vendors that connect to them rather than trying to break in from the outside. European security authorities, already facing an accelerating wave of data-theft campaigns against governments and enterprises, now have a fresh argument for segmenting access to national registers and treating suppliers' credentials as critical infrastructure.