Back to Feed
BreachesOct 5, 2026

Denmark population registry data breach affects 8.8 million people

Denmark's Central Population Register (CPR) suffered a data breach affecting 8.8 million individuals.

Summary

Denmark's Central Population Register (CPR) has reported a significant data breach impacting approximately 8.8 million individuals, including current residents, those who have moved abroad, and deceased persons. Threat actors exploited a private Danish company's legitimate access to the registry to steal personal information such as names, addresses, CPR numbers, and dates of birth. The Danish Data Protection Agency indicated that brute-forcing was used to enumerate CPR numbers before data extraction.

Full text

Denmark population registry data breach affects 8.8 million people By Bill Toulas October 5, 2026 11:21 AM 0 Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. This includes people who live in the country, individuals who have moved abroad, and also deceased people. The CPR is the country's national civil registry, containing personal information on residents, including names, addresses, dates of birth, marital status, and unique CPR identification numbers. According to a CPR announcement published earlier today, threat actors misused a private Danish company's legitimate access to the registry system to obtain names, addresses, CPR numbers, and other information relating to registered members. A separate announcement by the Danish Data Protection Agency says that the attack involved some form of brute-forcing to enumerate valid CPR numbers, and then extract the related data from each entry. The CPR system currently holds data for 11 million registered citizens, so the incident impacted a large portion (80%) of that, but not everyone. The security incident occurred in September 2026, but CPR administration became aware of the breach on October 2 and determined the size of the impact over the weekend. The private company's access to the registry has now been blocked, and police have launched an investigation, which is currently underway. "This is an extremely serious incident, which is why I have also informed Parliament’s Business and Digitalization Committee," stated Minister for Research, Education and Digitalization Christina Egelund. "Together with all relevant authorities, we are working to establish the full extent of the incident." Egelund said additional security measures have been implemented to prevent similar incidents on the CPR system, and urged citizens to stay on high alert for unsolicited communications. A dedicated "cyber hotline" has been set up for potentially affected individuals,, and help and guidance are also available online at sikkerdigital.dk. "In light of the incident, everyone is reminded never to disclose passwords or other confidential information in response to telephone calls, emails, or similar communications," the announcement warned. "This also applies even if the recipient appears to know your name, address, and CPR number." BleepingComputer has contacted the agency to learn more about the incident, including how the private company was compromised, but we have not received a response as of publication. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: OpenAI hacked Australian Medicare govt site, probed data providersSweden fines Miljödata $183,000 over breach affecting 2.2 millionJapan's Digital Agency says VPN flaw exposed 246,000 personnel recordsBerlin confirms data theft after Rhysida ransomware attack claimsSakura Internet hack exposes data of up to 1.36 million accounts

Entities

Central Population Register (product)Danish Data Protection Agency (vendor)threat actors (threat_actor)brute-forcing (technology)