Skip to content
European Crisis TV
LiveNationalConfirmed

Hackers breach Denmark's population registry, data of 8.8m exposed

Unauthorised access to Denmark's national CPR register exposed names, addresses and ID numbers of 8.8 million people, the digital ministry says.

By ECTV Crisis DeskEditor-in-chief: Erik FerdinandPublished 10 independent sources · 98% confidence
Location: Denmark. Open the live Europe Crisis Map

Hackers gained unauthorised access to Denmark's national population register, exposing the names, addresses and personal ID numbers of about 8.8 million people, the Ministry of Digital Government said on Monday, according to Kurier and in.gr. The register holds data on roughly 11 million people, including those who have died or emigrated, which is why the number of people affected exceeds Denmark's population of about six million, ERT News reported.

The breach affected the Central Person Register, known as CPR, which records living and deceased residents as well as people who have emigrated, Kurier reported. Authorities were alerted to an "anomaly" in the CPR system during September, the ministry said, according to Kurier. The ministry has not said how long the unauthorised access lasted before it was detected.

The unauthorised access was obtained through the legitimate access credentials of a Danish company, which has since been revoked, Kurier reported. "This is an extremely serious incident," Denmark's digital minister, Christina Egelund, said, according to Kurier and in.gr. She said officials, working with all relevant authorities, were still mapping the full extent of the breach, in.gr reported.

People whose names or addresses are registered as protected for safety reasons were not affected by the breach, in.gr reported. Authorities said they had introduced measures to prevent a repeat of the attack and had launched an investigation, though no suspects have so far been identified, Iefimerida reported.

Separately, Denmark's Technical University, DTU, said last week that unauthorised individuals had accessed its user database, potentially affecting around 200,000 current and former users, including staff, students, visitors and external partners, ERT News reported. It was not stated whether the two incidents are connected, and no evidence has been presented linking the DTU breach to the CPR register attack.

What we know

Not yet confirmed

  • Unconfirmed Whether the CPR breach is linked to a separate attack on Denmark's Technical University (DTU) reported last week has not been confirmed.

How each fact is established: Verified checked by an ECTV editorOfficial stated by an official body2+ outlets reported independently by two or more news organisations1 outlet reported by a single news organisation so farUnconfirmed claimed or reportedHow we label facts

Why it matters for Europe

Denmark's population registry underpins identity checks across the country's banking, healthcare and public administration systems, making a breach of this scale one of the largest data-security incidents reported in Europe this year. The exposure of names, addresses and personal ID numbers for nearly 9 million records creates a lasting risk of identity fraud for those affected, even though no financial data was reported stolen.

Sources

Reported by 10 reports from 10 independent outlets in 6 countries.

Source balance

Premium

See how the 10 outlets behind this story spread from left to right, and which are official or OSINT sources.

Free during the launch: create an account →Log inHow we rate sources

Intelligence file

Premium

See how we verified this story

Confidence and impact scores, 5 more sources, the full situation report and the event timeline.

Launch offer: free for members until 31 October 2026

Questions and answers

How many people are affected by the Denmark data breach?
About 8.8 million people had personal data exposed, the digital government ministry says.
What information was accessed?
Names, addresses and personal ID (CPR) numbers of registered residents, including people who have died or emigrated.
How did the hackers get in?
Through the legitimate access credentials of a Danish company, which authorities have since revoked.

This article was written with AI assistance from 10 verified reports and checked under the ECTV editorial policy. Spotted an error? Request a correction.

Share this story

denmarkcyberattackdata breachcpr registercybersecurity