
Hackers access personal data of 8.8 million people in Danish registry breach
Unauthorized users breached Denmark's central population register via a private company's credentials, exposing names, addresses, and CPR numbers for 8.8 million living, deceased, and emigrated individuals.
National population database breached
The Danish Ministry for Digital Affairs announced on Monday, 5 October 2026, that unauthorized individuals gained illegal access to personal data stored in the national population register, known as the CPR (Det Centrale Personregister). The cyber intrusion exposed confidential records belonging to approximately 8.8 million registered persons. The extracted data categories include full names, residential addresses, and CPR identification numbers, which function as Denmark's official social security and civil identification numbers. The administrative body managing the CPR register confirmed the illicit access after detecting irregular query volumes across its core systems. Danish law enforcement agencies and digital administration teams have launched an active investigation into the incident, though the individuals responsible for the breach remain unidentified.
Scope of affected demographic records
The CPR database serves as Denmark's central civil registry and contains personal files for approximately 11 million individuals in total. Because the national registry maintains demographic records across multiple decades, the 8.8 million compromised entries include current living residents, individuals who previously emigrated abroad, and deceased persons. Denmark currently has an active resident population of approximately 6 million inhabitants, according to national statistical records. Ministry officials specified that individuals enrolled in official name and address protection programs were excluded from the breach and suffered no exposure. The government confirmed that these protected identities remained shielded throughout the unauthorized queries.
- Total CPR records
- 11 million
- Records accessed
- 8.8 million
- Danish population
- 6 million
Exploitation of private enterprise credentials
The administration determined that the unauthorized access occurred through the legitimate credentials of a private Danish company holding authorized access to the CPR database. The CPR administrative body was first alerted to an anomaly inside the system on Friday, 2 October 2026, identifying irregular search activity that occurred during the month of September. Technical specialists worked throughout the weekend of 3–4 October 2026 to review access logs, assess system queries, and quantify the 8.8 million affected records. Following the verification of the data theft, authorities revoked the private company's access permissions to halt further queries. The ministry stated that immediate technical controls were enacted across the database infrastructure to prevent similar unauthorized access.
- Unauthorized queries are executed in the CPR database via private firm credentials.
- The CPR administration is alerted to a system anomaly from September.
- Technical specialists assess logs over the weekend and confirm 8.8 million accessed records.
- The Ministry for Digital Affairs publicly announces the breach and revokes contractor access.
Government reaction and security countermeasures
Danish authorities began inter-agency reviews across public digital infrastructure to assess the broader security implications of the breach. Christina Egelund, the minister in charge of digital affairs, addressed the data theft in an official government statement.
This is an extremely serious incident.
Egelund explained that government bodies are working collaboratively to establish the full technical perimeter of the data exposure.
Together with all relevant authorities, we are mapping the full scope of the incident.
The Ministry for Digital Affairs confirmed that new administrative safeguards have been implemented to restrict third-party query pathways and prevent duplicate breaches. Police investigators are continuing their forensic analysis of the access logs to identify the perpetrators.

