Data breaches

Denmark: 8.8 million population-register records exposed

A Danish company’s legitimate access to the CPR register was misused. The 8.8 million records also cover deceased people and former residents.

Conceptual illustration: Denmark: 8.8 million population-register records exposed
Conceptual illustration · SecurCheck

What is confirmed

Denmark’s Central Population Register (CPR) administration identified irregular activity on October 2 relating to September. Misuse of a company’s authorised access enabled personal data exposure.

Information disclosed on October 5 places the potentially affected record count at approximately 8.8 million, including names, addresses and CPR identification numbers. That figure is not the country's current population.

The Danish data protection authority was notified on October 4; investigations are ongoing.

What it means

Authorised third-party access is not a guarantee of confidentiality: permission scope and audit trails are critical.

Exposed identity records can be used to personalise impersonation and phishing attempts.

How the incident unfolded

Denmark’s Central Population Register (CPR) administration identified irregular activity on October 2 relating to September. Misuse of a company’s authorised access enabled personal data exposure.

Information disclosed on October 5 places the potentially affected record count at approximately 8.8 million, including names, addresses and CPR identification numbers. That figure is not the country's current population.

What it means for affected people

Authorised third-party access is not a guarantee of confidentiality: permission scope and audit trails are critical.

Exposed identity records can be used to personalise impersonation and phishing attempts.

Practical safeguards

Ignore unexpected requests for CPR numbers, documents or codes received by email or phone.

Verify sensitive requests directly with the relevant public service through its official website.

What to do

Ignore unexpected requests for CPR numbers, documents or codes received by email or phone.

Verify sensitive requests directly with the relevant public service through its official website.

Organisations should minimise third-party data access and audit bulk exports.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. The Register — 6 octobre 2026
  2. Help Net Security — 6 octobre 2026