The breach, which occurred in September but was discovered on October 2, compromised names, addresses and Danish social security numbers. The CPR is the government's central database of citizen information, used for accessing tax and other public services. While Denmark's current population is around 6 million, the database contains records on approximately 11 million people, including deceased individuals and Danish citizens living abroad, with some records dating back decades.
Minister Christina Egelund said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." Certain companies in Denmark are permitted to query the CPR database to verify individuals' identities with the government, and the attackers exploited that access channel. The government has declined to identify the company involved or attribute the attack to any specific group or nation-state.
The breach follows a pattern of cyberattacks targeting national identity databases worldwide, including a 2016 incident affecting millions of Turkish citizens and multiple exposures of India's Aadhaar system. Danish authorities have not disclosed what remedial steps are being taken or whether affected individuals will be notified directly.