Particle.news

Denmark’s Population Register Breached; 8.8 Million CPR Numbers Exposed

Abuse of a private supplier’s legitimate access creates long-term identity fraud and state-level targeting risks because CPR numbers are permanent identifiers.

Overview

  • The CPR administration says it detected irregular activity on the evening of Friday 2 October and now confirms roughly 8.8 million records containing names, addresses and CPR numbers were exposed from the Central Person Register.
  • Authorities blocked the implicated supplier’s access, reported the case to Datatilsynet and opened a police investigation while the minister ordered a full security review of the register.
  • The exposed dataset covers current residents as well as people who have died or moved abroad, which makes the information unusually deep and permanent and means the risk cannot be undone by resetting passwords.
  • Experts warn the breach came via abuse of a lawful third‑party connection, showing how a single compromised supplier account can read large volumes of sensitive records and enabling scammers to use personal details for phishing and impersonation.
  • Security advice for people includes watching for phishing, checking accounts for fraud, changing reused passwords and enabling multi‑factor authentication; experts urge governments to limit supplier access, monitor query patterns and apply data‑centric protections.