The breach was detected on October 2 after irregular activity during September. The CPR administration said it established the scale of the breach over the weekend and has blocked the unnamed company's access. The affected total exceeds Denmark's current population of around 6 million because the register contains about 11 million records, including individuals who have died or moved abroad. The ministry noted that names and addresses of persons who chose name and address protection were not exposed.
Digitization minister Christina Egelund told TV 2 it was too soon to say whether the country would issue all-new CPR numbers, one of the solutions proposed. Danish cybersecurity specialist Jan Kaastrup argued that treating CPR numbers as secrets is a "broken" approach and that a number alone should not be accepted as proof of identity. "We live in a digitalized society, and therefore we should have much better identification systems," he said.
Egelund described the company whose access was abused as "small." Private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions requiring legally entitled processing and advance identification of a defined group of individuals. The CPR administration has asked the ministry why such broad access was granted. The agency has notified the Danish Data Protection Agency, and police are investigating.