Hackers grab personal data of 8.8 million people in Denmark's national registry breach
Denmark's digital affairs ministry said on Monday that hackers abused a Danish company's legal access to the country's CPR civil registry to obtain names, addresses and personal ID numbers of around 8.8 million people. The breach has been reported to the data protection authority and is under police investigation.
Hackers broke into Denmark’s national civil registry and obtained the names, addresses and personal ID numbers of around 8.8 million registered people, the country’s digital affairs ministry said on Monday (https://punchng.com/denmark-probes-hack-of-national-database-affecting-8-8m-people/).
The attackers abused a Danish company’s legitimate access to search the CPR system, Denmark’s central person register, to pull data on around 8.8 million registered persons — living, emigrated and deceased. People registered with name and address protection were not affected, the ministry said in its press release (https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/).
Administrators noticed irregular behaviour in the CPR system on the evening of Friday 2 October, and over the weekend confirmed the unauthorised access. The registry holds around 11 million registered persons, even though Denmark has only about six million inhabitants.
The company’s access has been revoked, the incident reported to Datatilsynet, Denmark’s data protection authority, and police are investigating with the relevant authorities. Digital Affairs Minister Christina Egelund called it a “deeply serious incident”, said she had briefed parliament’s business and digitalisation committee, and ordered a full security review of the CPR system. The investigation is in its early phase and officials say it is not yet possible to say who is behind the breach. Egelund urged all citizens to stay vigilant and check guidance at sikkerdigital.dk.
More on this topic: all Technology stories


