Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Danish ID Register Data Breach Exposes 8.8 Million Records, Exceeding Country's Resident Population




Denmark's Central Population Register (CPR), which tracks the country's residents and citizens, has been breached, exposing sensitive personal information of approximately 8.8 million people. The breach, which was discovered in October 2026, reveals that an unauthorized party abused the legitimate access granted to the CPR by a private Danish company, exposing names, addresses, identification numbers, and other personal details of the affected individuals. The incident highlights the need for robust security measures and better identification systems in Denmark's CPR, as well as greater scrutiny of the access granted to private companies handling sensitive personal information.

  • The Denmark Central Population Register (CPR) has been breached, exposing sensitive personal information of approximately 8.8 million people.
  • The breach was caused by unauthorized access granted to a private Danish company, exposing names, addresses, identification numbers, and other personal details.
  • Security measures in place for the CPR have been criticized, with experts arguing that treating CPR numbers as secrets is not sufficient to prevent breaches.
  • The incident highlights the need for robust security measures and better identification systems in the CPR.
  • The breach has raised concerns about the use of private companies' access to sensitive personal information and the need for greater regulation and oversight.
  • The CPR administration is working to block the company's access and establish what happened, with the government calling for a review and strengthening of security measures.



  • Denmark's Central Population Register (CPR), which is responsible for tracking the country's residents and citizens, has been breached, exposing sensitive personal information of approximately 8.8 million people. The breach, which was discovered in October 2026, reveals that an unauthorized party abused the legitimate access granted to the CPR by a private Danish company, exposing names, addresses, identification numbers, and other personal details of the affected individuals.

    The CPR administration, which is responsible for ensuring the security and integrity of the register, stated that it became aware of the irregular activity in September 2026 and established the scale of the breach over the weekend. The administration has notified the Danish Data Protection Agency and is working with specialists and relevant authorities to determine the cause of the breach and prevent future incidents.

    Jan Kaastrup, a Danish cybersecurity specialist, has expressed concerns about the security measures in place for the CPR, stating that treating CPR numbers as secrets was a "broken" approach. Kaastrup argued that a number alone should not be accepted as proof of identity, citing the need for more robust identification systems in the digital age.

    Christina Egelund, the digitization minister, has also weighed in on the issue, describing the company whose access was abused as "small." Egelund noted that private businesses can obtain CPR data under section 38(1) of the Danish Civil Registration System Act, subject to restrictions set out in the ministry's access terms. However, she also acknowledged that the current system may not be sufficient to prevent such breaches.

    The breach highlights the need for robust security measures and better identification systems in Denmark's CPR. With a population of around 6 million people, the CPR contains information of over 55,000 individuals living in Greenland, who also use CPR numbers for healthcare, tax services, and banking. The ministry noted that the register contains approximately 11 million records, including those of people who have died or moved abroad, which explains why the affected total exceeds Denmark's current population.

    The breach has also raised concerns about the use of private companies' access to the CPR. While the company whose access was abused was described as "small," the incident highlights the need for greater scrutiny of the access granted to private companies handling sensitive personal information.

    The CPR administration has taken steps to block the unnamed company's access and is working with specialists and relevant authorities to establish what happened. The incident serves as a reminder of the importance of data protection and the need for robust security measures to prevent such breaches in the future.

    In light of the breach, the Danish government has been called upon to review and strengthen the security measures in place for the CPR. The incident has also raised questions about the use of private companies' access to sensitive personal information and the need for greater regulation and oversight.

    As the investigation into the breach continues, it remains to be seen what measures will be taken to prevent similar incidents in the future. However, one thing is clear: the incident highlights the need for greater attention to data protection and security in Denmark's CPR.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Danish-ID-Register-Data-Breach-Exposes-88-Million-Records-Exceeding-Countrys-Resident-Population-ehn.shtml

  • https://www.theregister.com/security/2026/10/06/denmarks-id-register-spills-more-peoples-details-than-the-country-has-residents/5301307


  • Published: Tue Oct 6 08:31:26 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us