Hackers steal 8 million records from Danish government citizen database

Breach of Central Person Register is largest in country's history, says minister

By LineZotpaper
Published
Read Time2 min
The Danish government has confirmed that hackers stole the personal information of approximately 8 million citizens and residents from the country's Central Person Register (CPR), in what ministers are calling a "serious incident" and the largest data breach in Denmark's history.

The breach, which occurred in September but was discovered on October 2, compromised names, addresses and Danish social security numbers. The CPR is the government's central database of citizen information, used for accessing tax and other public services. While Denmark's current population is around 6 million, the database contains records on approximately 11 million people, including deceased individuals and Danish citizens living abroad, with some records dating back decades.

Minister Christina Egelund said the unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." Certain companies in Denmark are permitted to query the CPR database to verify individuals' identities with the government, and the attackers exploited that access channel. The government has declined to identify the company involved or attribute the attack to any specific group or nation-state.

The breach follows a pattern of cyberattacks targeting national identity databases worldwide, including a 2016 incident affecting millions of Turkish citizens and multiple exposures of India's Aadhaar system. Danish authorities have not disclosed what remedial steps are being taken or whether affected individuals will be notified directly.

§

Analysis

Why This Matters

  • The compromise of a national identity database exposes nearly every Danish citizen and resident to long-term risks of identity theft and fraud.
  • The breach exploited a legitimate business-to-government data access channel, raising questions about how such access is monitored and secured.
  • It underscores the vulnerability of centralized citizen registries that store decades of sensitive personal data.

Background

Denmark's Central Person Register (CPR) is a foundational government database, assigning every resident a unique social security number used for taxation, healthcare and other official purposes. Private companies are sometimes granted access to verify information against the register, a convenience that has now become an attack vector. This is not the first major breach of a national identity system: similar incidents have occurred in Turkey, India and elsewhere, often exposing hundreds of millions of records.

Key Perspectives

[Danish Government]: Minister Christina Egelund described the breach as a "serious incident," but has not released details on the attackers or the specific company whose access was abused. Authorities are focused on investigation and containment. [Affected Citizens and Residents]: Up to 8 million people may have had their personal data stolen, including sensitive identifiers that cannot be easily changed. The risk of fraud and phishing attacks is heightened. [Critics/Skeptics]: Security experts are likely to question why a single company's compromised access could expose the entire database, and whether the system needs stronger access controls or auditing.

What to Watch

  • Whether the Danish government identifies the company whose access was abused and whether it faces penalties.
  • Any announcement of individual notifications or credit monitoring services for affected citizens.
  • Potential legislative changes to tighten third-party access to the CPR system.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.