The Danish government has announced that unknown intruders obtained the names, addresses and personal identification numbers of nearly 8.8 million people from the country’s central population register — in what is believed to be the largest data breach in Danish history.
The breach, disclosed on Monday, October 5, was discovered when the CPR administration noticed irregular activity in its systems on the evening of Friday, October 2. Investigators traced the unauthorized access back to September. No system was forced: the intruders operated through the legal access of a Danish company whose permissions to query the register they hijacked.
An Entire Country in One File
The figure of 8.8 million exceeds Denmark’s population of around 6 million, because the register also holds records of people who have died and Danes living abroad. In total the CPR system contains around 11 million records — meaning four out of five were consulted.

The CPR number is the ten-digit personal identifier assigned to every Danish resident since 1968. It is the key to banking, healthcare and tax services — and unlike a password, it follows a person for life and cannot be revoked once exposed. Only people placed under special name-and-address protection were exempt from the breach.
“A Profoundly Serious Incident”
Christina Egelund, Minister of Research, Education and Digital, described the leak as a “profoundly serious incident.” She informed the relevant parliamentary committee and ordered a thorough review of the register’s security. The Danish data protection authority, Datatilsynet, has been brought in, and police are investigating. The perpetrators remain unknown.
The administration has cut off the compromised company’s access to the register. A helpline has been opened from 8 a.m. to midnight in the coming days, and authorities warn citizens never to share codes by telephone or email — even when the caller already knows their name, address and CPR number.
FAKTA
- Names, addresses and CPR numbers of around 8.8 million people were exposed from Denmark’s central population register.
- The breach was discovered on October 2 and disclosed by the government on October 5, 2026.
- The intruders abused a Danish company’s legal access — no system was hacked or forced.
- The CPR is a ten-digit personal ID assigned since 1968, used for banking, healthcare and taxes.
- Minister Christina Egelund called it a “profoundly serious incident” and ordered a full security review.
- A public helpline is open from 8 a.m. to midnight; only those under name-and-address protection were spared.
What Happens Now
The ministry cautions that the figures may change as the investigation progresses. The promised security review will cover a system created in 1968 that still underpins Denmark’s digital identity — a reminder that centralized identity registers carry risks no password can match.

For more political news, visit Watan News International.



































