Tidavo
Tuesday 6 October 2026

Data Intruders Use Corporate Credentials to Expose Millions of Danish Population Records

An unauthorized query campaign through a private company's account extracted civil registry details for nearly nine million people, including past residents and the deceased.

6 Oct 2026

Intruders have compromised the personal records of roughly 8.8 million individuals stored within Denmark's central population registry, pulling details that encompass both current citizens and millions who have passed away or relocated abroad.

The breach came to light after Denmark's Ministry of Digitalization announced on October 5 that external parties had improperly queried the national database, known as the Central Person Register or CPR.

The registry serves as the administrative backbone of Danish public life, assigning a unique personal identification number to every resident and tracking essential civic details throughout a person's life.

Rather than forcing their way through the central database's primary defenses, the intruders routed their searches through an established access channel granted to a private Danish company. That business possessed legitimate authority to look up records within the CPR system.

By misusing that commercial credential, the attackers systematically gathered names, home addresses, and personal identification numbers across millions of entries.

The sheer volume of the exposed files, standing at 8.8 million, is notably larger than the current population of Denmark, which counts fewer than six million living residents. The discrepancy arises because the CPR retains historical records over decades, maintaining profiles for former residents and citizens long after their deaths.

In the wake of the incident, government authorities issued public guidance urging citizens to stay alert, though full details on protective measures were not immediately published.

Crucial aspects of the intrusion remain unexplained. Officials have not named the private enterprise whose access was hijacked, nor have they stated how the credentials were obtained or how long the unauthorized lookups continued before being discovered.

The Register , The Hacker News