Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Denmark's National Population Register Breach: A Comprehensive Analysis of the Cyber Attack and its Implications




Denmark's national population register has been compromised in a major cyber attack, leaving approximately 8.8 million individuals' sensitive data exposed. The breach was carried out by unauthorized parties who gained access to the register via a private Danish company's lawful right to look up records in the Central Person Register (CPR). The breach highlights the need for robust security measures to protect sensitive information, and raises questions about the adequacy of the CPR Act.

  • Denmark's national population register was compromised in a major cyber attack, exposing approximately 8.8 million individuals' sensitive data.
  • The breach was carried out by unauthorized parties who gained access to the register via a private Danish company's lawful right to look up records in the Central Person Register (CPR).
  • The breach lasted for approximately 10 days and was carried out through automated lookups to identify valid personal identification numbers (CPR numbers).
  • The Danish government has acknowledged that the safeguards around this kind of access had not been solid enough and that alarms should have gone off given how long it lasted.
  • The breach has raised concerns about the security of sensitive information and the need for better protection.
  • The Danish government has announced plans to conduct a full security review of the register and has begun measures to prevent a repeat of the breach.
  • The breach has also raised questions about the adequacy of the CPR Act, which governs the use of the CPR number.



  • Denmark's national population register, a centralized database containing the personal information of its citizens, has been compromised in a major cyber attack. The breach, which has left approximately 8.8 million individuals' sensitive data exposed, was carried out by unauthorized parties who gained access to the register via a private Danish company's lawful right to look up records in the Central Person Register (CPR).

    According to the Danish digitalization ministry, the breach lasted for approximately 10 days in September, during which time the attackers conducted a large number of automated lookups to identify valid personal identification numbers, known as CPR numbers. The ministry has informed people to never give passwords or other confidential information to anyone who calls or emails, even if they seem to know those details.

    The register's administration has stopped the company's access and reported the case to Datatilsynet, Denmark's data protection authority. Police are investigating the matter, and the ministry has begun measures to prevent a repeat of the breach.

    The breach highlights the need for robust security measures to protect sensitive information. The Danish government's own digitalization ministry has acknowledged that the safeguards around this kind of access had not been solid enough, and that alarms should have gone off given how long it lasted.

    The CPR number, a 10-digit number consisting of 6 digits for the date of birth and 4 serial digits, is used to identify a person for the purpose of receiving data on their current name and address, unless protected. The register's guidance states that companies may only get data on people they already deal with, such as customers or employees. However, the ministry's statement does not explain how one company's access under those rules came to cover about 4 in 5 people on the register.

    The breach has raised concerns about the security of sensitive information and the need for better protection. The Danish government's response to the breach has been criticized for not being transparent enough, and for not providing adequate information about the breach.

    In light of this breach, the Danish government has announced plans to conduct a full security review of the register. Datatilsynet is also examining what happened, how it could happen, and who is responsible for handling the personal data. The ministry has also begun measures to prevent a repeat of the breach.

    The breach has also raised questions about the adequacy of the CPR Act, which governs the use of the CPR number. The act allows companies to have register data delivered on people they have already identified one by one, but it does not provide adequate safeguards to prevent unauthorized access.

    In conclusion, the breach of Denmark's national population register highlights the need for robust security measures to protect sensitive information. The Danish government's response to the breach has been criticized for not being transparent enough, and for not providing adequate information about the breach. The breach has also raised questions about the adequacy of the CPR Act, and the need for better protection.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Denmarks-National-Population-Register-Breach-A-Comprehensive-Analysis-of-the-Cyber-Attack-and-its-Implications-ehn.shtml

  • https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html


  • Published: Tue Oct 6 02:09:33 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us