Massive breach exposes personal data of nearly 9 million Danish residents

Denmark's Central Population Register suffered a significant data breach in September 2026 affecting approximately 8.8 million individuals, representing 80% of the registry's total population records. Attackers exploited legitimate access from a private company to extract names, addresses, CPR identification numbers, and other personal information through brute-force enumeration of valid CPR numbers. Authorities have blocked the compromised access, launched a police investigation, and implemented additional security measures while urging citizens to remain vigilant against potential scams.
The Denmark Central Population Register serves as the nation's official civil database, housing records for roughly 11 million individuals including current residents, expatriates, and deceased persons. The September breach allowed unauthorized actors to systematically query the system using a compromised company's legitimate credentials, systematically testing combinations to identify valid identification numbers and retrieve associated personal details. Danish authorities discovered the intrusion on October 2 and spent the following weekend assessing its full scope before announcing findings on October 5.
Response efforts have included immediate revocation of the affected company's system access, launch of a police investigation, and deployment of enhanced security protocols. Officials established a dedicated support line and online resource portal to assist potentially impacted residents while cautioning against social engineering attempts that may exploit the now-public disclosure of names and addresses.
The breach affects approximately 80 percent of Denmark's registered population, potentially exposing individuals to identity theft, fraud, and targeted scams leveraging disclosed personal identifiers. Attackers possessing names, addresses, and CPR numbers may conduct convincing phishing campaigns or impersonation schemes. The incident underscores systemic risks when third-party companies retain broad database access and the vulnerability of even national infrastructure to credential compromise. Affected citizens face potential financial and reputational harm, though impact severity depends partly on attackers' intentions and downstream data usage.