Tuesday, October 6, 2026
Tech Beat
Oct 5, 2026, 2:58 PMCybersecurity

Denmark CPR Breach Exposes Records of 8 Million People

Denmark says hackers stole CPR records on 8 million people, exposing names, addresses and identity numbers by abusing a company's lawful database access.

Listen to this briefingAudio briefing

Summary

Denmark confirmed on October 5, 2026, that hackers stole most of its Central Person Register, or CPR, affecting about 8 million citizens and residents, including people abroad and the deceased. The stolen records include names, addresses, Danish social security numbers and other information. Danish minister Christina Egelund called it a serious incident.

The September breach was discovered October 2 and exploited a Danish company's lawful ability to search CPR data, access some companies receive to verify identities. The government has not identified the attackers. CPR holds about 11 million records, some decades old, despite Denmark's current population of roughly 6 million, including government issued identity numbers used for taxes and services. Believed to be Denmark's largest data breach, it follows a 2016 attack affecting millions of Turkish citizens and exposures involving India's Aadhaar national identity database.

Positives

  • The October 2 discovery brought the September breach to the Danish government's attention.
  • Denmark publicly confirmed the theft and identified the categories of personal information exposed.
  • Officials traced the unauthorized searches to abuse of a Danish company's lawful CPR access.
  • The disclosed access route gives authorities and authorized companies a specific security weakness to examine.

Risks & concerns

  • About 8 million citizens and residents had records stolen, including people abroad and the deceased.
  • Hackers obtained names, addresses, Danish social security numbers and other personal information.
  • Most contents of the CPR were stolen from a database containing about 11 million records.
  • Some compromised data dates back decades and includes identity numbers used for taxes and government services.
  • The Danish government has not identified who conducted the September attack.
  • The incident is believed to be the largest data breach in Denmark's history.
Primary sourceTechCrunchhttps://techcrunch.com/2026/10/05/hackers-steal-8-million-citizens-records-from-danish-government-database/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecurityOct 5

MCP Trust Flaws Let AI Agents Turn Prompts Into Internal Attacks

CybersecurityOct 4

Google Pauses Open Source Bug Bounty Over Invalid AI Reports

CybersecurityOct 2

Apple Tightens macOS Full Disk Access as Meta Muse Raises AI Privacy Risks