Denmark confirmed that unauthorized parties accessed Central Population Register (CPR) records belonging to approximately 8.8 million people, exposing names, addresses and CPR numbers. Attackers misused an unnamed private Danish company’s authorized access during September. The initial entry method remains unknown, and authorities have not identified a specific vulnerability or threat group. Protected names and addresses were excluded from the unauthorized access, but officials did not confirm that other information belonging to those individuals was unaffected.
CPR administrators detected unusual activity on October 2 and subsequently blocked the company’s access, engaged specialists and notified Denmark’s Data Protection Authority. Police are investigating, while Minister Christina Egelund requested a thorough review of CPR security; authorities said preventive measures were already underway. Officials warned residents that the exposed information could support convincing phishing attempts and expanded access to security guidance. The incident highlights the risk posed by third-party access to sensitive population data, even where that access was originally authorized.

See attribution, scope, and your downstream exposure.
13 events from the most recent confirmed update back to the earliest known activity.
Denmark confirmed in an official statement that unauthorized parties accessed CPR records belonging to approximately 8.8 million people. Authorities did not disclose the implicated company, the initial access method, a specific vulnerability, or a threat-group attribution.
The CPR administration detected unusual system behavior on Friday evening, October 2, triggering investigation of the unauthorized access.
CPR staff observed irregular system behavior during September, before the breach detection on October 2 already recorded in the timeline.
Unauthorized parties used an unnamed private Danish company's lawful CPR access to obtain records belonging to approximately 8.8 million people. Exposed information included names, addresses, and CPR numbers.
Danish digitization minister Christina Egelund said it was too early to determine whether Denmark would issue new CPR numbers following the breach affecting approximately 8.8 million people.
Denmark's Data Protection Agency, Datatilsynet, opened a case to investigate what happened, how the unauthorized access was possible, and who was responsible for processing the affected personal data.
Denmark's Data Protection Agency described a very large number of automated searches intended to identify valid CPR numbers. The attackers used an unnamed domestic company's legitimate access to the register.
Danish authorities warned that exposed personal details could make fraudulent messages and calls appear convincing, and advised residents not to disclose passwords or confidential information in unexpected communications. The Cyberhotline extended its opening hours to provide additional security guidance.
Minister Christina Egelund informed Parliament's Business and Digitalization Committee and requested a thorough security review of CPR. Officials said preventive measures had begun but did not disclose their technical scope.
Police and other relevant authorities began investigating how the company's permitted access was misused on such a large scale. The inquiry was described as being at an early stage.
The CPR administration notified Denmark's Data Protection Authority of the personal-data breach.
Over the weekend following detection, officials established that unauthorized access covered approximately 8.8 million registered people. The review found that protected names and addresses were excluded, without establishing whether other fields for those individuals were unaffected.
Authorities blocked the implicated company's access to CPR and engaged specialists to map the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
24 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcecysecurity.news
Open sourcemalware.news
Open sourcetheregister.com
Open sourceufm.dk
Open sourcesikkerdigital.dk
Open sourcedatatilsynet.dk
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.