Hackers Hijacked One Danish Company's Access to the National Register and Pulled Data on 8.8 Million People
Names, addresses and lifetime ID numbers for 8.8 million people walked out of Denmark's national register through one private company's legitimate login. Those numbers can't be changed.

Denmark said Monday that unauthorized parties accessed the names, addresses and CPR numbers of about 8.8 million people in its Central Person Register. Nobody broke down the front door. The attackers misused the legitimate access of one private Danish company to quietly pull records out of the national register.
A CPR number is Denmark's 10-digit personal ID, roughly comparable to a US Social Security number. It begins with a person's date of birth, unlocks healthcare, banking and government services, and is meant to last a lifetime. That makes this leak hard to clean up.
More people than live in Denmark
Denmark's population is just over six million, so 8.8 million is not the current population. The register holds about 11 million records, including people who have moved abroad and the deceased.
Danish law lets companies with a legitimate interest look up certain register information about people they have already identified. The company involved has not been named. According to the official announcement, CPR administration has cut off its access.
Automated searches in September
Officials spotted irregular activity on the evening of Friday, October 2. Over the weekend, investigators found it had taken place during September. The Danish Data Protection Agency, notified Sunday, described a very large number of automated searches aimed at identifying valid CPR numbers.
Authorities have no information on who was behind it, and the police investigation is at an early stage. People registered for name and address protection did not have their names and addresses exposed.
"A deeply serious incident"
"This is a deeply serious incident," said Christina Egelund, minister for research, education and digitalisation, who added that authorities are still mapping the full extent of the incident. She briefed Parliament's Business and Digitalization Committee and ordered a broad security review of the CPR system. The national digital security hotline is running extended hours, 8 a.m. to midnight.
Officials are warning people not to hand over passwords or confidential information by phone or email, even if the caller already knows their name, address and CPR number. That is exactly the kind of detail that makes a scam call sound legitimate.
"A compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure," said Dray Agha, a senior security operations manager at Huntress.
A familiar pattern
It is the biggest CPR incident since 2015, when two unencrypted CDs holding CPR details on more than five million people were mistakenly delivered to the Chinese Visa Application Centre in Copenhagen. Argentina, Turkey, India and Israel have all suffered population-scale registry leaks.
Identity data keeps leaking through trusted third parties. Last month the ID scanning firm IDScan.net disclosed that an unauthorized party may have reached customer cloud data, and a Pentagon file-sharing server left Social Security numbers of nearly 3 million troops exposed for months. Denmark's version is worse in one way: its leaked numbers were designed to last a lifetime.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free