Denmark's Central Population Register (CPR) warned that threat actors misused a private Danish company's legitimate access to the national civil registry to obtain personal data on approximately 8.8 million of the country's 11 million registered individuals (≈80%), including people who have moved abroad and deceased persons. The Danish Data Protection Agency said the attack involved brute-forcing to enumerate valid CPR numbers and then extracting each entry's names, addresses, dates of birth, marital status and unique CPR identification numbers. The intrusion occurred in September 2026; CPR administration became aware on 2 October and determined the scale over the weekend. The private company's access has been blocked, police have opened an investigation, and Minister Christina Egelund (Research, Education and Digitalisation) has informed Parliament's Business and Digitalization Committee, while a dedicated hotline and updated guidance aim to blunt follow-on identity fraud from the exposed identifiers. Why it matters: this is a registry-integrity and identity-fraud risk at national scale — a national population roll depleted to near-total coverage through a trusted intermediary's credentials rather than a direct state-system breach, and a model for how legitimate access can be weaponised against an entire population.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-10-06 |
| Source | BleepingComputer |
| Reliability | Tier 2 |