A significant data breach has rocked Denmark, impacting the Central Population Database and exposing the personal information of approximately 8.8 million individuals. The incident, revealed by the Danish government on Monday, involved unauthorized access to sensitive data including names, addresses, and crucial CPR numbers – Denmark’s personal identification numbers.
How the Breach Occurred
The Danish government stated that the breach stemmed from unidentified individuals misusing the legitimate access credentials of a private Danish company. These actors then conducted unauthorized queries against the CPR system, the core of Denmark’s highly digitized public administration.
The involved company’s system access has since been completely revoked, and law enforcement is actively investigating the matter. Authorities have indicated that the perpetrators behind the breach remain unknown at this time.
Official Response and Concerns
Danish Minister for Digitalization, Christina Egelund, described the event as “extremely serious.” In response, she has ordered a comprehensive security review of the CPR system. Minister Egelund also urged the public to remain vigilant against potential suspicious phone calls and phishing emails that might follow this incident.
Understanding the CPR System
The CPR system is a cornerstone of Denmark’s digital public services. Every Danish resident is assigned a unique 10-digit CPR number, which is extensively used for identity verification across government services, financial transactions, banking, and healthcare.
While Denmark’s current population is around 6 million, the Central Population Database holds approximately 11 million historical records, encompassing data of deceased individuals and those who have moved abroad. This broader scope explains the large number of affected records.
Timeline and Scope of the Breach
According to officials, abnormal activity was first detected on October 2nd. Further investigation over the weekend confirmed that the unauthorized queries took place during September. The government clarified that individuals who have opted for privacy protection, such as hiding their real address and identity, were not affected by this specific breach.
The incident highlights the vulnerabilities inherent in large-scale digital population databases and underscores the ongoing challenge of securing sensitive personal information in an increasingly interconnected world. The Danish authorities are working to ascertain the full extent of the breach and to implement measures to prevent future occurrences.








