8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Description
Denmark's Central Person Register (CPR) suffered a data breach impacting approximately 8.8 million individuals. Hackers exploited a Danish company's lawful access to the CPR system to steal personal information including names, addresses, and CPR numbers. The breach was discovered after abnormal system behavior was detected in September. The breach does not affect individuals who opted for name and address protection. CPR revoked the company's access, notified authorities, and is investigating the incident while planning to enhance security measures.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The data breach at Denmark's Central Person Register involved unauthorized access through a Danish company that had lawful access rights under Danish law. Hackers abused this access to exfiltrate personal data of about 8.8 million registered individuals, including living and deceased persons. The stolen data includes names, addresses, and CPR numbers, which are equivalent to Social Security numbers. The breach was detected following abnormal activity notifications, leading to immediate termination of the company's access and notification of the Danish Data Protection Agency and law enforcement. The CPR system is reviewing and improving its security policies to prevent recurrence. The identity of the threat actor remains unknown.
Potential Impact
The breach exposed sensitive personal information of approximately 8.8 million individuals, including names, addresses, and national identification numbers (CPR numbers). This data exposure could lead to identity theft, fraud, and privacy violations for affected individuals. The breach includes data of both living and deceased persons but excludes those who registered with name and address protection. The incident undermines trust in the CPR system and may have regulatory and legal consequences for involved parties.
Defensive Guidance
CPR has revoked the compromised company's access to the system and notified the Danish Data Protection Agency and police. The organization is conducting an investigation and reviewing its security policies to enhance protections. Individuals are advised to be cautious of unsolicited requests for personal information. No further immediate action is specified by the vendor advisory; ongoing monitoring and policy improvements are underway.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/8-8-million-impacted-by-data-breach-at-denmarks-central-person-register/","fetched":true,"fetchedAt":"2026-10-06T09:48:21.212Z","wordCount":947}
Threat ID: 6ac4c3e52cdf04f656948d3f
Added to database: 10/06/2026, 09:48:21 UTC
Last enriched: 10/06/2026, 09:48:25 UTC
Last updated: 10/06/2026, 15:48:23 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.