
Unauthorized access to Denmark’s Central Person Register (CPR) exposes names, addresses and personal identification numbers, raising concerns over identity theft and cyber-enabled fraud.
Denmark is investigating a major cybersecurity incident involving its Central Person Register (CPR), after unauthorized individuals gained access to personal information associated with approximately 8.8 million registered people. The incident has been described by Danish authorities as a serious security breach, although investigators have not yet confirmed that ransomware was involved.
The compromised information reportedly includes names, addresses and CPR numbers, Denmark’s personal identification numbers. The scale of the incident exceeds the country’s resident population of roughly six million because the CPR database also contains records relating to people who have died, emigrated or otherwise remain registered in the system.Â
According to Denmark’s Ministry of Research, Education and Digitization, the unauthorized access was achieved by misusing the legitimate access privileges of a private Danish company that was authorized to search the CPR system. Authorities have since suspended the company’s access and begun working with cybersecurity specialists and law-enforcement agencies to establish exactly how the incident occurred.Â
Digital Minister Christina Egelund described the incident as deeply serious and said a comprehensive security review of the CPR system had been ordered. Authorities are also investigating whether existing controls around third-party access were sufficient. Reporting from Danish media indicates that the suspicious activity continued for approximately ten days during September before being detected by the CPR administration on October 2.Â
The incident highlights a growing cybersecurity challenge: third-party and privileged access can become a significant attack vector even when the core government database itself has not been directly breached. Compromised credentials, excessive permissions, inadequate monitoring and weak access controls can allow attackers to exploit legitimate pathways into sensitive systems.
For affected individuals, the exposure of names, addresses and national identification numbers could create opportunities for identity theft, phishing, social engineering and financial fraud. Danish authorities have therefore urged citizens to exercise increased caution, particularly when receiving unsolicited calls, emails or messages from individuals who appear to possess legitimate personal information.
Authorities have clarified that the unauthorized access did not include names and addresses of individuals who had specifically registered for name and address protection. The Danish Data Protection Agency has been notified, while police and relevant government bodies are continuing their investigation.Â
The Denmark incident serves as another warning for governments and enterprises worldwide: protecting sensitive databases requires more than securing the database itself. Zero-trust architecture, strong identity and access management (IAM), privileged-access controls, continuous monitoring, anomaly detection and rigorous third-party risk management are increasingly essential to prevent legitimate credentials from becoming the gateway to large-scale data exposure.
Join our LinkedIn group Information Security Community!











