Denmark's Central Population Register has disclosed a data breach affecting roughly 8.8 million registered individuals, the CPR announced. Those exposed include current residents of the country, people who have moved abroad, and deceased individuals. The registry, known as the CPR, is the nation's national civil registry and holds names, addresses, dates of birth, marital status, and unique CPR identification numbers. The system currently contains data on 11 million registered citizens, meaning the incident touched about 80 percent of that total.
According to the CPR, attackers abused the legitimate access that a private Danish company held on the registry system to pull names, addresses, CPR numbers, and other information tied to registered members. A separate announcement from the Danish Data Protection Agency said the attack used some form of brute-forcing to enumerate valid CPR numbers and then extract the data attached to each entry. The private company's access to the registry has since been blocked.
The security incident took place in September 2026, but CPR administration did not learn of the breach until October 2 and spent the weekend determining how many people were affected, the CPR said. Police have opened an investigation that is currently underway. BleepingComputer reported that it contacted the agency for more detail, including how the private company was compromised, and had not received a response as of publication.
Minister for Research, Education and Digitalization Christina Egelund called the incident extremely serious and said she had informed Parliament's Business and Digitalization Committee. She said authorities are working together to establish the full scope of the incident. Egelund also said additional security measures have been put in place to prevent similar incidents on the CPR system and urged citizens to remain on high alert for unsolicited communications.
A dedicated cyber hotline has been set up for potentially affected individuals, and help and guidance are available online at sikkerdigital.dk. In its announcement, the CPR reminded everyone never to disclose passwords or other confidential information in response to telephone calls, emails, or similar communications. That warning applies even when the person making contact appears to know the recipient's name, address, and CPR number, the announcement said.
The source article also carried a promotion for a two-hour digital summit featuring Mikko Hypp nen and security leaders from the NFL, CHANEL, and Atlassian, focused on AI-speed attacks. A separate headline referenced a statement from Japan's Digital Agency that a VPN flaw exposed 246,000 personnel records. Neither item was connected to the Danish registry breach in the source material.
More cybersecurity news from TechManNews.





