Denmark Faces Major Data Breach, Affecting Nearly 9 Million Residents
In a significant breach of personal data, Denmark’s Central Register of Persons has fallen prey to unauthorized access, impacting a staggering 8.8 million individuals. This data breach, revealed by the Danish digital affairs ministry on October 6, 2026, has raised serious alarms among citizens and officials alike, as it concerns sensitive information related to social security and banking across the nation.
The breached system, which is crucial for identifying citizens in various societal functions, includes not only current residents but also records for individuals who have passed away or left the country, totaling around 11 million entries. Notably, Denmark’s actual population stands at just six million, leading to widespread concerns about the implications of such a far-reaching exposure of personal details.
Among the data accessed were names, addresses, and CPR numbers—unique ten-digit identifiers assigned to citizens. The government noted that those who opted for name and address protection managed to safeguard their confidential information from the breach. Christina Egelund, Denmark’s digital affairs minister, publicly condemned the incident as "deeply serious," emphasizing that the authorities are actively working to ascertain the full extent of this grave lapse in security.
In light of the breach, the Danish Agency for Social Security issued an urgent advisory, warning both authorities and the public to be especially vigilant against potential fraud attempts. These fraud attempts may involve calls or emails containing information about citizens, misused by malicious actors in an effort to exploit the stolen data.
Egelund also announced a comprehensive security review of the Central Register of Persons. While initial investigations indicate that this incident might not be the result of a direct cyberattack, it was revealed that attackers exploited a small Danish company’s legal access to the register. According to the government, this company misused its privileges, which should have limited access to the register, leading to unauthorized searches involving vast amounts of data.
The breach was first detected when unusual activity in the system came to light, following a sizable invoice generated by the company responsible for the unauthorized access. Mikkel Leihardt, an official from the digital affairs ministry, reported that the compromised access had been in use for around ten days before being flagged and subsequently shut down. He asserted, “We must conclude that the security has not been adequate,” highlighting the failure to monitor access adequately.
In response to the breach, the Danish Data Protection Agency has launched an investigation. They are scrutinizing the excessive number of automated searches conducted against the CPR system to gain valid CPR numbers. Despite regulations implemented in 2013 intended to tighten access to the CPR system, these provisions primarily affected e-commerce functionalities rather than larger-scale lookups from companies. This lack of stringent measures has led to significant vulnerabilities being exposed, placing citizens at risk of identity theft and digital fraud.
Laila Reenberg, director of the Danish Agency for Community Safety, signaled that identity theft is likely among the primary motives for the breach and announced that residents could no longer rely solely on their CPR numbers for identification.
Interestingly, this data breach is not an isolated incident in Denmark, as attention has also turned to the Technical University of Denmark. On the same day as the CPR breach was discovered, the university revealed that its identity and access management system, DTUBasen, had suffered a "targeted cyberattack." This incident has reportedly allowed perpetrators to download substantial volumes of data, affecting around 40,000 active users and about 160,000 former users, including students, employees, and external partners. The university acknowledged that determining the exact information compromised is challenging, further complicating the matter.
Bjarke Bak Christensen, the university’s director, made a statement expressing regret over the “serious attack” and the uncertainty it has generated among those affected. He emphasized that the first priority is to assess the attack’s extent, mitigate its impacts, and inform individuals regarding the necessary steps to protect their information.
As the Danish government grapples with these serious breaches, the nation remains on high alert, reflecting the urgent need for heightened security measures and protection strategies in an increasingly digital world. The ramifications of these breaches may not only affect individual privacy but also undermine public trust in digital systems and the governance that oversees them.
