A cyberattack on the country’s Central Person Register has resulted in the largest data breach in Danish history, leaking personal information belonging to roughly 8 million citizens.
A cyberattack on Denmark’s Central Person Register (CPR) has exposed personal data for roughly 8 million residents, marking the largest data breach in the country’s history.
What happened
The breach was discovered on October 3, 2026, when security analysts noticed unauthorized access to the CPR database, which stores identifiers, birth dates, addresses and other civil‑registry details for all Danish citizens and residents.
According to the Danish Data Protection Agency, the attackers exfiltrated the data over several weeks before the intrusion was detected, exploiting a vulnerability in a legacy authentication module.
Scope of the compromised data
The stolen records include full names, CPR numbers, dates of birth, and residential addresses. Financial information such as bank account numbers was not part of the leak, but the exposed identifiers can be combined with other public sources to facilitate identity theft.
- Full name and CPR number
- Date of birth
- Current and previous addresses
- Family relationships recorded in the register
Response from authorities
Prime Minister Mette Frederiksen ordered an emergency session of the National Security Council, and the Ministry of Justice launched a forensic investigation with assistance from the Danish Defence Intelligence Service.
The government has urged affected individuals to monitor their credit reports and has set up a dedicated hotline for support and guidance on protecting personal information.
Potential impact and next steps
Experts warn that the breach could lead to a surge in phishing attacks targeting Danish citizens, as the CPR number is a key credential for many online services.
Legislators are now debating stricter security standards for government databases, including mandatory multi‑factor authentication and regular third‑party security audits.
"This is a wake‑up call for all public sector entities to reassess their cyber‑defences," said a senior analyst at the Danish Cyber Security Center.
For a detailed account of the breach and its implications, see TechCrunch coverage of the Danish CPR breach.