IT-PUB NEWS

Danish government confirms CPR breach exposed 8 million

06.10.2026 12:03 • Author: IT-PUB
Danish government confirms CPR breach exposed 8 million

Officials said attackers stole names, addresses and CPR numbers after abusing a Danish company’s lawful access to the national register.

The Danish government has confirmed a major breach of its Central Person Register, or CPR, after attackers stole most of the database’s contents. The incident affects about 8 million citizens and residents, including people living abroad and deceased individuals. Officials called it a serious case because the stolen data includes personal details used to identify people and access public services. For Denmark, that makes this more than a large leak.

The scale is striking, but so is the target. The CPR is one of Denmark’s core identity systems, holding government-issued identity numbers along with names, addresses and other information tied to tax payments and official services. Although Denmark’s population is around 6 million, the database contains records for about 11 million people in total, including older data going back decades.

Denmark says attackers hit a core identity register

According to the Danish government, the attack targeted the CPR, the national database that stores citizens’ information. The system serves as a key reference point for identity verification in the country, which makes any exposure especially sensitive.

Minister Christina Egelund described the breach as a “serious incident” in a statement. The government said the stolen information included names, addresses, Danish social security numbers and other personal data. It did not say who was behind the attack.

What sets this case apart is the scale. The government said the breach is believed to be the biggest in Denmark’s history. As IT-PUB News reports, the number of records in the CPR is larger than the country’s population because the register also includes people abroad and deceased individuals.

Officials say lawful access was abused

The breach happened in September and was discovered on October 2, according to the government. Officials said the unauthorized access was obtained by “abusing a Danish company’s lawful access to search for information in the CPR system.”

That is a crucial detail. The government’s account suggests the attackers did not simply break into the system in a conventional way. Instead, they misused access that a Danish company already had for checking people’s information against the state register.

The statement does not identify the company or explain exactly how the access was abused. Still, it points to a problem that goes beyond technical defenses alone: legitimate access can become a security risk when it is misused.

The stolen CPR data has direct real-world value

The CPR is not just another government database. It contains the identity number people use for tax and other public services, which means the stolen records could be useful for impersonation or other forms of fraud. The government did not describe any specific misuse, but the type of information exposed is highly sensitive.

For ordinary people, the case shows how personal data stored in one central system can be copied and removed at scale. For businesses, it is a reminder that access to public databases carries serious responsibility, especially when companies are allowed to verify customer information against state systems.

The breach also puts pressure on trust in digital government infrastructure. Centralized databases can make services easier to use, but they also create a large target. When a system holding millions of identities is exposed, the consequences can reach well beyond the immediate security failure.

The breach fits a wider pattern of identity database attacks

Denmark’s case is not the first attack on a national identity database. The source notes that it follows similar cyberattacks targeting government identity systems, including a 2016 breach affecting millions of Turkish citizens and several exposures linked to India’s Aadhaar database.

Those earlier incidents help explain why breaches like this draw so much attention. National identity databases are not ordinary corporate records. They are tied to access to services, legal identity and day-to-day administration, so a breach can affect people on a broad scale and for a long time.

In Denmark’s case, the government has confirmed the incident and the size of the loss, but not the identity of the attackers. What is already clear is that a central state register was accessed improperly, a vast amount of personal data was taken, and the case is being treated as one of the country’s most serious cyber incidents.


Improve SEO for a small/medium business website for $50