Denmark CPR Data Breach Exposes Records of 8.8 Million People
Denmark says attackers accessed personal records of about 8.8 million people after abusing a private company’s legitimate access to the CPR database.
Denmark has confirmed a major breach of its Central Person Register, or CPR, after unauthorised actors accessed personal information belonging to about 8.8 million people by abusing a Danish company’s legitimate access to the system.
In an official statement, the government said the exposed data included names, addresses, CPR numbers and other information. The incident occurred in September and was discovered on Oct. 2. Authorities have since blocked the company’s access and notified police and data protection officials.
The breach reaches beyond Denmark’s current population
The number of affected records exceeds Denmark’s population because the CPR contains decades of historical data, including records for people living abroad and those who have died. The registry is widely used for identity, tax and other government services.
Officials have not identified who was behind the breach. They said the attackers gained access by misusing a private company’s lawful ability to search the CPR database rather than directly breaking into the system.
The incident echoes other national identity data exposures
The breach is believed to be the largest in Denmark’s history and follows other major exposures involving centralised identity systems. In Turkey, for example, a 2016 leak exposed personal information linked to millions of citizens, with BBC reporting highlighting the privacy and fraud risks created when national identity datasets are compromised.
CPR numbers play a central role in verifying identity and accessing services, making the stolen data particularly sensitive. Authorities are still investigating and have not disclosed whether the information has been misused.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0