Denmark is investigating a major security incident involving its Central Person Register (CPR) after unauthorized individuals gained access to the names, addresses, and CPR numbers of approximately 8.8 million registered people.
The Danish authorities said the attackers misused the legitimate access of a private Danish company that was authorized to search the CPR system. The company itself has not been publicly identified, and authorities have not yet disclosed who was behind the unauthorized activity or exactly how the access was compromised.
The CPR is Denmark’s national population register and contains information on around 11 million registered people. That figure includes people currently living in Denmark, people who have moved abroad and deceased individuals, meaning the number of records involved in the incident is larger than Denmark’s current population.
According to Denmark’s Ministry of Research, Education and Digitalization, the unauthorized access included names, addresses and CPR numbers. People who had registered for name and address protection were not included in the affected information, according to the authorities.
The incident was first detected on the evening of October 2, when CPR administrators noticed unusual activity in the system. A review over the following weekend found that unauthorized access had taken place during September. Authorities have since stopped the company’s access to the CPR system and launched an investigation into what happened.
The case has been reported to Denmark’s Data Protection Agency and is being investigated by police together with other relevant authorities. The Danish government has also ordered a broader security review of the CPR system and said additional measures are being introduced to prevent a similar incident from happening again.
Danish officials are warning people to be especially careful with unexpected emails, text messages and phone calls. Security experts have also warned that exposed names, addresses and identification numbers could make phishing and other fraud attempts more convincing because criminals can use legitimate personal information to make their messages appear more credible.
However, a CPR number alone is not enough to impersonate someone for sensitive digital services, as Denmark relies heavily on additional authentication through systems such as MitID. Authorities are still working to determine the full extent of the incident and whether the exposed information has been copied, misused or distributed further.



