Security News

Danish Population Register Breach Shows How Supplier Access Can Expose Millions

The Record · 5 Oct 2026
Key Takeaway Review which suppliers have direct access to your systems and data, limit that access to what is necessary, and monitor it for unusual activity such as large volumes of automated requests.

Denmark is investigating a data breach affecting around 8.8 million people after unauthorised users gained access to its national population register, the government said on Monday. The attackers exploited the legitimate access of an unnamed domestic company to the Central Person Register (CPR), compromising names, addresses and CPR numbers. These 10-digit numbers begin with a person's date of birth and are used for healthcare, banking and government services. They are roughly comparable to Social Security numbers in the United States.

Officials first detected irregular activity on Friday and determined over the weekend that the breach occurred during September. Denmark's Data Protection Agency described it as a very large number of automated searches aimed at identifying valid CPR numbers. No perpetrators have been named. Research, education and digitalisation minister Christina Egelund called it a deeply serious incident, ordered a broad security review and extended the digital security hotline hours from 8 a.m. to midnight. Because CPR numbers are meant to last a lifetime, there are fears the risks could have a very long tail.

Experts pointed to the supplier connection. Dray Agha of Huntress said a compromised account at a single supplier can bypass an organisation's core security controls and turn a legitimate connection into a massive data exposure. The source notes similar national registry breaches in Argentina, Turkey, India and Israel.

data breach supply chain risk third-party access Denmark identity data
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.