Misuse of CPR Register Access Exposes Personal Data of About 8.8 Million People in Denmark

· Original article ↗

Summary

Unknown actors misused a private company’s lawful access to Denmark’s CPR register, exposing names, addresses and CPR numbers for about 8.8 million people. Authorities cut off the company’s access and police are investigating.

Key points

  • Unknown actors abused a private Danish company’s legitimate search access to the Central Person Register; authorities say this was not a direct hack of government servers.
  • Names, addresses and CPR numbers were accessed for about 8.8 million registered people, including living, emigrated and deceased persons; the figure may change as authorities complete their review.
  • People with name and address protection were not exposed in that data.
  • The CPR administration cut off the company’s access, reported the case to Denmark’s Data Protection Agency and is mapping what happened.
  • Police are investigating, the company has not been named, and the actors’ identities are unknown.
  • Authorities warn that exposed details could enable targeted phishing and phone scams, and urge people to verify unexpected contacts through official channels.
  • The government has ordered a security review of the CPR system and says measures to prevent similar incidents are underway.

Article Details

Victim Organization
CPR-administrationen (Danish Central Person Register)
Incident Type
Unauthorized access and bulk extraction of register data through misuse of a private company's lawful CPR search access
Data Types Exposed
  • Names
  • Addresses
  • CPR numbers
Affected Records
Approximately 8.8 million registered persons, according to a preliminary official count
Operational Impact
The CPR administration cut off the company's access and began a security review. No service disruption was reported.
Claim Status
confirmed

People

Countries

Industries