Hackers hit Denmark: 8.8 million people exposed in a massive data breach
Attackers have leveraged stolen access since at least September.

Image by Martin Sylvest Andersen/Getty Images
- Denmark says attackers accessed CPR records for about 8.8 million registered people.
- Exposed data includes names, addresses, and CPR numbers, but not protected name and address records.
- Attackers abused legitimate company access and had used the system since at least September.
- Authorities revoked the access, opened investigations, and warned citizens to watch for fraud attempts.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Denmark has suffered a massive data breach affecting approximately 8.8 million registered people. Attackers leveraged stolen access to the population database, leaking names, addresses, and personal identification numbers.
The Danish Central Person Register (CPR) administration, a government body overseeing the national database that tracks basic personal information of all living and deceased citizens, reported a severe security incident.
Unauthorized attackers abused legitimate access belonging to a Danish company to access the CPR system and search for information.
The intruders, “among other things,” have gained access to the names, addresses, and CPR numbers of approximately 8.8 million registered citizens in the CPR system, according to the official statement.
Every registered individual in Denmark receives a unique CPR number, a similar identifier to a social security number or national ID.
The CPR system contains a total of 11 million registered citizens, including those currently alive and residing in the country, as well as the deceased and those who have moved abroad.
Those who have chosen to register with name and address protection haven’t been exposed in the leak.
Check if your data was exposed
Find out if your email and related personal information have appeared in known data breaches.
“This is a deeply serious incident,” said Christina Egelund, Danish Minister of Research, Education, and Digitalization.
“Together with all relevant authorities, we’re in the process of mapping the full extent of the incident.”
Hackers had siphoned data since September
Irregular behavior in the CPR system was first detected on the evening of Friday, October 2nd, 2026. Attackers had been accessing the database since an unspecified time in September.
The CPR administration has revoked the access abused by attackers, reported the incident to the Danish Data Protection Authority, and the case is being investigated by the police in cooperation with relevant authorities. A thorough security review is being carried out.
“As a consequence of the incident, initiatives have been launched in relation to CPR to prevent similar incidents,” reads the translation of the press release.
The authorities are also alerting citizens that stolen personal information may be misused for fraud and urging them to exercise caution. Citizens in Denmark are warned to be extra cautious about unsolicited communications, such as SMS messages, calls, and emails that use personal information about them, not to share any passwords, one-time codes, or other sensitive information, and to monitor their credit history.
Denmark relies heavily on MitID (two-factor authentication) for sensitive digital actions, and the attackers cannot impersonate someone with a CPR number alone.
Cybersecurity experts noted that this incident highlights the inherent risks of highly centralized systems, especially when private companies are granted direct access to sensitive data.
“A compromised account at a single supplier can bypass an organization's core security controls and turn a legitimate connection into a massive data exposure,” said Dray Agha, senior manager of security operations at Huntress.