← Back to the feed

Intruder exploits Denmark’s population register, exposing 8.8 million people’s data

The Register ·

An unauthorized party exploited legitimate access to Denmark's Central Population Register to expose personal data on approximately 8.8 million people. The breach, discovered on 2 October after irregular activity in September, included names, addresses, identification numbers and other personal details. Because CPR numbers are essential for Danish public services, healthcare, tax and banking, the breach affects access to multiple critical systems.

The CPR register contains roughly 11 million records, including deceased individuals and those who have relocated abroad, which explains why the exposed total exceeds Denmark's 6 million residents. An unnamed private company's access to the system was exploited by an unauthorized party. Officials indicated uncertainty about whether all-new CPR numbers will be issued, and cybersecurity specialists have questioned whether CPR numbers alone should serve as identity proof, calling for more robust identification systems.

  • Data breach exposed 8.8 million records from Denmark's population register.
  • CPR numbers essential for healthcare, tax, banking and public services.
  • New CPR numbers may be issued; experts question current identity system.

New here? Start with this

Denmark's Central Population Register, known as CPR, is a state database holding personal information on millions of people, including names, addresses and identification numbers. CPR numbers are essential to accessing healthcare, pensions, tax systems and banking in Denmark.

An unauthorized person accessed this register by exploiting legitimate access held by a private company, exposing data on approximately 8.8 million people. The CPR contains around 11 million records, including those of deceased people and residents abroad, explaining why the exposed number exceeds Denmark's population of roughly 6 million.

The breach is significant because CPR numbers serve as a primary form of identity verification across multiple Danish systems including healthcare, finance and public services. Cybersecurity specialists have questioned whether CPR numbers should continue to serve as the sole form of identity proof following this exposure.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

A strong case for systemic overhaul would be that CPR numbers themselves have become a liability precisely because they function as a universal master key for Danish society. Once compromised, they compromise access to healthcare, banking, taxation and government services simultaneously. Rather than relying on a single identifier that, once breached, requires notification of 8.8 million people, Denmark should transition to systems requiring multiple forms of verification—biometric data, hardware tokens, or distributed authentication—so that no single breach can unlock all critical services.

The case against

The pragmatic counterargument is that CPR numbers themselves didn't fail; the security layers around them did. Reissuing numbers would burden millions of citizens, disrupt essential services across healthcare, banking and government for years, and carry enormous costs—all for uncertain benefit if access controls remain weak. The real lesson is that Denmark must dramatically strengthen how it grants and monitors database access, implement continuous auditing of suspicious activity, require supplementary verification for high-risk transactions, and restrict which private companies can access the full register. These measures address the actual vulnerability—inadequate governance of legitimate access—rather than abandoning a system that works well when properly protected.

Software

Read the full article at the source →

Originally published by The Register as “Denmark’s ID register spills more people’s details than the country has residents”.