Denmark's digitalization ministry has confirmed that unauthorized parties gained access to personal data on an estimated 8.8 million people held in the country's Central Person Register (CPR) — the national identity database that underpins nearly every public and private service in Denmark, from banking to healthcare.
What happened
The exposure didn't come from a direct break-in to the register itself. Instead, it ran through a legitimate channel: a private Danish company holds lawful permission to look up CPR records for people it already does business with — customers or employees, for example. According to the ministry, someone with access to that company's systems ran a very large volume of automated lookups over roughly ten days in September, apparently working to identify which ten-digit CPR numbers were actually in use.
A staff member at the register's administration flagged the unusual activity on October 2. By the following weekend, officials understood the scale: records tied to about 8.8 million people — living residents, Danish citizens living abroad, and deceased individuals — had been reachable through the compromised access. The register holds roughly 11 million entries in total, meaning the incident touched close to four out of every five records on file, in a country of under 6 million people.
The company's access to the register has been cut off, and the case has been referred to Datatilsynet, Denmark's data protection authority, as well as the police. Officials haven't yet said publicly how the intruders got into the company's systems in the first place, whether the data was copied or used, or who is behind it.
What was — and wasn't — exposed
Under Denmark's CPR Act, companies with legitimate access can retrieve a person's current name and address, plus status flags like a death, a move abroad, or a credit warning — but not the CPR number itself. That distinction matters here: the automated activity appears to have been aimed at discovering which CPR numbers exist and are valid, exploiting the fact that a CPR number has only 10,000 possible combinations for any given date of birth (six digits for birth date, four serial digits, with the last digit indicating sex). Records protected under Denmark's name-and-address protection scheme were not included.
Why it matters
A CPR number isn't supposed to function as a secret or a password — Denmark's own guidance says it shouldn't be the sole proof of identity — but in practice it's requested constantly, by banks, landlords, clinics, and employers. Large-scale exposure of which numbers are valid, paired with names and addresses pulled through the same access, gives scammers exactly the raw material they need for convincing phishing, impersonation, and social-engineering attacks that reference real personal details. Denmark's digitalization minister has publicly acknowledged that the safeguards around this kind of third-party access "had not been solid enough," given how long the activity went undetected.
What to do
- Be skeptical of unexpected contact. Texts, calls, or emails that reference your name, address, or other personal details aren't automatically trustworthy just because the sender "knows" things about you.
- Never click links in unsolicited messages. Go to the official site directly, or call the organization's published number to verify.
- Never share MitID credentials, one-time codes, passwords, or card numbers with anyone who contacts you first.
- Consider setting a credit warning (kreditadvarsel) through borger.dk — it flags your CPR number so lenders take extra care before extending credit in your name.
- Danish residents with questions can contact the national Cyberhotline for digital security for guidance during the response to this incident.
The ministry has requested a full security review of the register, and Datatilsynet is investigating how the access was obtained and who is responsible for handling the data. We'll update this article as Danish authorities release more detail.
