Hackers Extract 8 Million Records from Denmark’s Central Register

Denmark has suffered its most severe breach in history after hackers infiltrated the Central Person Register (CPR), a national database containing comprehensive details on citizens and residents. Around 8 million records were exfiltrated, including those of deceased individuals and Danes living abroad.

The CPR system logging names, addresses, Danish social security numbers, and other personal identifiers was compromised in September and the breach was discovered on October 2, federal officials confirmed. While Denmark’s population is approximately 6 million, the database holds records for about 11 million people — capturing decades of data tied to residents and citizens. The government classifies the incident as a “serious incident.”

How the Intrusion Happened

The attack stemmed from the misuse of authorized access by a Danish firm that had legitimate permission to query the CPR system. It was through exploiting this lawful access that attackers extracted sensitive personal data. So far, authorities have not made public who orchestrated the breach.

Wider Impact & Comparisons

This represents the most extensive data breach in Denmark’s history, putting at risk a trove of personal data. Similar exposures have occurred elsewhere, such as in 2016 when millions of Turkish citizens had their national identity database compromised, and in India with recurring incidents involving the Aadhaar identity system. These cases highlight persistent vulnerabilities in national ID registries globally.

Danish Minister Christina Egelund described the breach as serious and confirmed that stolen data includes core identifiers such as names, addresses and social security numbers. The damage may include both living and deceased individuals’ records.

What’s Next

Authorities have yet to identify the attackers, and investigations continue. Given the scale and sensitivity of the data involved, the breach is being considered not just a domestic crisis, but one that carries implications for privacy, identity theft, and national security protection.

It remains unclear how the exposed data might be used or shared, though the inclusion of social security numbers and other identifiers suggests potential for misuse. Individuals affected could face risk of fraud and forced identity disclosure.

The government is assessing damage control measures, exploring options for notifying affected individuals, strengthening CPR access protocols, and auditing third-party access rights. Legal repercussions and regulatory fallout may follow, both domestically and under EU data protection frameworks.

Analysis: This breach underscores the inherent risks in centralized identity systems—even when access appears lawful. Trust in national registers depends heavily on robust oversight of who can access data, and how credentials and authorizations are managed. Denmark’s crisis should serve as a wake-up call: identity checks must go hand in hand with continuous audits, strict access controls, and rapid breach detection. What remains now is not only to contain the fallout, but to demonstrate how such oversight will be concretely improved.