What is confirmed
Denmark’s Central Population Register (CPR) administration identified irregular activity on October 2 relating to September. Misuse of a company’s authorised access enabled personal data exposure.
Information disclosed on October 5 places the potentially affected record count at approximately 8.8 million, including names, addresses and CPR identification numbers. That figure is not the country's current population.
The Danish data protection authority was notified on October 4; investigations are ongoing.
What it means
Authorised third-party access is not a guarantee of confidentiality: permission scope and audit trails are critical.
Exposed identity records can be used to personalise impersonation and phishing attempts.
How the incident unfolded
Denmark’s Central Population Register (CPR) administration identified irregular activity on October 2 relating to September. Misuse of a company’s authorised access enabled personal data exposure.
Information disclosed on October 5 places the potentially affected record count at approximately 8.8 million, including names, addresses and CPR identification numbers. That figure is not the country's current population.
What it means for affected people
Authorised third-party access is not a guarantee of confidentiality: permission scope and audit trails are critical.
Exposed identity records can be used to personalise impersonation and phishing attempts.
Practical safeguards
Ignore unexpected requests for CPR numbers, documents or codes received by email or phone.
Verify sensitive requests directly with the relevant public service through its official website.
What to do
Ignore unexpected requests for CPR numbers, documents or codes received by email or phone.
Verify sensitive requests directly with the relevant public service through its official website.
Organisations should minimise third-party data access and audit bulk exports.
Use the related SecurCheck tool, then confirm important decisions with an official source.