Data breach at Denmark’s population register exposes 8.8 million people
A data breach at Denmark’s Central Population Register (CPR) has exposed the personal information of 8.8 million people. These include people living in Denmark, deceased people and citizens who have moved abroad.

The CPR is Denmark’s national register of residents, and the 10-digit CPR number it assigns to each person is used for everything from taxes and healthcare to banking.
The CPR administration learned on the evening of Friday, 2 October 2026, that there had been irregular activity in the system during September. Over the weekend, it discovered the extent of the unauthorized access, and on Sunday, 4 October, it notified the Danish Data Protection Agency (Datatilsynet).
The Danish Ministry of Research, Education and Digitalisation disclosed the incident on 5 October.
“This is a deeply serious incident, which I have therefore also informed the Danish Parliament’s Business and Digitalisation Committee about. Together with all relevant authorities, we are in the process of mapping the entire extent of the incident,” said Christina Egelund, Minister of Research, Education and Digitalisation.
“We have already launched initiatives in relation to CPR to prevent similar incidents. I have also asked for a thorough security review of the CPR system,” added Egelund.
The attackers obtained names, addresses and CPR numbers by misusing a private Danish company’s legitimate access to search the CPR system. According to the announcement, they stayed within the limits of the information that private companies are allowed to retrieve.
The CPR holds about 11 million records, so the breach covers about 80% of the register. “The review carried out shows that the unauthorized access does not include names and addresses of persons who have chosen to register with name and address protection,” the ministry stated.
The company’s access has been cut off, and police are investigating the case together with other relevant authorities.
The ministry has not named a suspect, saying it is “not possible to say anything about who is behind it” at this stage of the investigation.
The Danish Data Protection Agency has opened a case and is looking into what happened, how it was able to happen, and who is responsible for the processing of the personal data involved.
The ministry is warning that the stolen data could be used in fraud attempts and advises citizens never to hand over passwords or other confidential information over the phone, by email or through similar channels, “even if the recipient apparently knows your name, address and CPR number.”
“I urge all citizens to be alert at this time and in the coming period, and to seek information at sikkerdigital.dk,” Egelund concluded.