The Denmark data breach has exposed the names, addresses and CPR numbers of approximately 8.8 million people after unauthorized users exploited a Danish company’s legitimate access to the country’s Central Person Register (CPR), according to the Danish government.
The CPR administration became aware of irregular behavior in the system on October 2, after identifying activity that had occurred during September. An investigation found that unauthorized individuals had used a private Danish company’s legal access to search the CPR system and obtain information on millions of registered people.
The CPR currently contains information on approximately 11 million registered people, including those who are living in Denmark, people who have moved abroad and deceased individuals.
Denmark Data Breach Involved Legitimate CPR Access
The Denmark data breach did not result from unauthorized access being granted directly to the attackers. Instead, unauthorized users abused a private company’s legitimate access to the CPR system.
Under Section 38 of Denmark’s Civil Registration Act, private companies with a legitimate interest can receive information from the CPR about specific groups of people they have individually identified in advance. Companies must also be entitled to receive the information under the General Data Protection Regulation and Denmark’s Data Protection Act.
The investigation found that unauthorized individuals used this legitimate access to retrieve information from the register.

The exposed information includes names, addresses and CPR numbers, which serve as personal identification numbers in Denmark. The CPR administration said the unauthorized access did not include the names and addresses of people who had registered for name and address protection.
Investigation Into CPR Data Breach Continues
The CPR administration has stopped the company’s access to the system and is working with specialists and relevant authorities to establish how the incident occurred.
The case has been reported to the Danish Data Protection Authority, while police are investigating in cooperation with other relevant authorities.
Authorities said the investigation remains in its early stages, and it is not yet possible to identify who was responsible for the unauthorized access. The CPR administration also warned that further investigation could lead to changes or clarification of the information currently available about the incident.
Denmark’s Minister of Research, Education and Digitalisation Christina Egelund described the incident as serious and said a thorough security review of the CPR system would be conducted. Additional measures have also been launched to prevent similar incidents.
What the Denmark Data Breach Means for Citizens
Authorities have reminded citizens not to provide passwords or other confidential information during phone calls or email exchanges, even when the person making contact appears to know their name, address or CPR number.
Guidance is available through Denmark’s Sikker Digital service, while the Cyberhotline for digital security has extended its opening hours from 8 a.m. to midnight in the coming days.
The incident also highlights the risks associated with legitimate access to sensitive databases. In this case, the access used to obtain the information was originally available to a private company under Denmark’s existing rules for accessing CPR data.
Cybersecurity Awareness Month Puts Data Protection in Focus
The Denmark data breach comes during October’s Cybersecurity Awareness Month, a period focused on improving awareness of digital security risks. The incident highlights why protecting access to sensitive personal information remains an important part of cybersecurity.
For organizations handling large volumes of personal data, the case also shows the importance of monitoring legitimate access and identifying unusual activity. However, Danish authorities have stressed that the investigation is still underway and that the full circumstances of the incident have yet to be established.

