Denmark Hack Exposes Personal Data of 8.8 Million People in 'Extremely Serious' Registry Breach
Hackers reached the national CPR registry through a company with legal access; attackers not yet identified
2 min read

File photo: Christiansborg Palace, seat of the Danish parliament and government offices, seen from the Marble Bridge in Copenhagen. Photo: Moahim, CC BY-SA 4.0, via Wikimedia Commons
Denmark has suffered a major data breach after hackers broke into the country's national population registry and accessed the personal details of 8.8 million people, the government said on Monday.
What was taken
The digital affairs ministry said "unauthorised individuals obtained illegal access" to names, addresses and CPR numbers, Denmark's national identity and social security numbers, Euronews reported.
The number of people affected is far larger than the country's population of around six million. That is because the national registry holds information on about 11 million people, including those who have died or emigrated, according to Danish authorities.
Danish news agency Ritzau reported that the register also includes information on church membership and details of legal incapacitation and restrictions on legal capacity, DW said.
Minister: 'extremely serious'
Digital affairs minister Christina Egelund described the breach in stark terms. "This is an extremely serious incident," she said.
"Together with all the relevant authorities, we are in the process of mapping out the full extent of the incident," Egelund added, according to the ministry's press release quoted by Euronews.
The ministry said it was first alerted to an "anomaly" in the system "during September", DW reported.
How the hackers got in
According to the government, the attackers did not break into the registry directly. Instead, they gained access by hacking into a Danish company that legally had access to the registry. Initial findings suggest the breach was carried out using the legitimate login credentials of that local company, DW reported, adding that the means used to gain access has since been cut off.
Authorities said they have no information on who carried out the attack. An investigation has been launched, and the company involved has not been publicly named.
Why it matters
The CPR number is a key piece of personal information in Denmark, widely used to identify residents in dealings with public services. The breach covers records of both current residents and people who have died or left the country.
Officials have not said whether the stolen data has appeared online or been misused. They say they are still mapping the full extent of the incident together with the relevant authorities, and more details are expected as the investigation continues.
