A significant breach of Denmark's Central Person Register (CPR) has compromised data on roughly 8.8 million people, the government announced Monday. The attack leveraged an unnamed domestic firm's legitimate connection to the system to extract names, addresses and CPR numbers—identifiers functionally equivalent to U.S. Social Security numbers.

The CPR database contains records on approximately 11 million individuals, encompassing current residents, emigrants and deceased persons. Denmark's total population stands at just over six million.

Christina Egelund, minister for research, education and digitalisation, characterized the breach as deeply troubling. She announced a comprehensive security audit of the system and extended operating hours for Denmark's digital security hotline, which will now run from 8 a.m. to midnight in the coming days.

Authorities detected suspicious activity in the CPR system on Friday. Weekend investigations revealed the compromise occurred in September, though officials have not disclosed details about the attackers' identity.

Denmark's Data Protection Agency learned of the incident Sunday and characterized it as involving extensive automated queries designed to discover valid CPR numbers.

The 10-digit CPR identifiers, which start with a person's birth date, serve as the foundation for healthcare, banking and public administration in Denmark. Because these numbers remain valid throughout a person's lifetime, experts warn that victims may face prolonged exposure to identity theft and fraud.

Large-scale breaches of national population databases have struck multiple countries in recent years, including Argentina (2021), Turkey (2016), India (2018) and Israel (2006).

This incident demonstrates the inherent risk of highly centralized national databases when private companies are granted direct access to sensitive records. A compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure.

Dray Agha, senior manager of security operations at Huntress

Centralised systems like this should be treated with the utmost importance. Overall, it is very positive to see the current transparency, especially the extended hours on the digital security hotline. These behaviours can indicate that response plans are in place and being followed.

Nathan Davies-Webb, principal consultant at Acumen Cyber

This represents the most significant breach of the CPR system since 2015, when two unencrypted CDs holding CPR data on over five million people were mistakenly sent to the Chinese Visa Application Centre in Copenhagen. Officials stated at that time that no evidence emerged of the information being copied or distributed.