Denmark Population Registry Breach Exposes Data of 8.8 Million People

Summary
Denmark's Central Population Register says attackers misused a private company's access and brute-forced CPR numbers to access personal data on about 8.8 million people. The company's access has been blocked, and police are investigating.
Key points
- The breach exposed names, addresses, CPR identification numbers, and other information belonging to about 8.8 million people, including residents, people who moved abroad, and deceased individuals.
- The Danish Data Protection Agency said attackers used brute force to enumerate valid CPR numbers and retrieve associated records.
- The attackers misused a private Danish company's legitimate access to the registry; how the company was compromised remains unknown.
- The incident occurred in September 2026. The registry administration became aware of it on October 2 and assessed the impact over the weekend.
- The breach affected about 80% of the 11 million people whose data is held by the registry.
- The company's registry access has been blocked, police have opened an investigation, and additional security measures have been implemented.
Article Details
- Victim Organization
- Central Population Register (CPR)
- Incident Type
- Unauthorized extraction of registry data through misuse of a private company's legitimate access; the Danish Data Protection Agency reported brute-force enumeration of valid CPR numbers.
- Disclosure Date
- 2026-10-05
- Data Types Exposed
- Names
- Addresses
- CPR identification numbers
- Other unspecified information relating to registered individuals
- Affected Records
- Approximately 8.8 million registered individuals, including people living abroad and deceased people; about 80% of the registry's 11 million entries.
- Operational Impact
- The private company's registry access was blocked, additional security measures were implemented, and police opened an investigation. No registry outage was reported.
- Claim Status
- confirmed