Threat Intelligence

Danish Population Register Data on 8.8 Million People Accessed Through a Company's Lookup Rights

The Hacker News · 6 Oct 2026
Key Takeaway If your business has approved access to a third-party or government data service, monitor that access for unusual volumes of activity and be ready to cut it off quickly.

Denmark's digitalization ministry said on October 5 that unauthorised parties gained access to the names, addresses and personal identification numbers of about 8.8 million people, living and dead, held in the national Central Person Register (CPR). The attackers used a small private Danish company's lawful right to look up records. According to the data protection authority, Datatilsynet, a very large number of automated lookups were made to identify valid CPR numbers. It describes the numbers as allegedly retrieved and has not yet assessed the case.

The access lasted about 10 days in September. An employee of the register's administration noticed unusual activity on Friday, October 2, and the scale became clear over the weekend. The company's access has been stopped, the case has been reported to Datatilsynet, and police are investigating. The ministry says the figure is not yet final. It covers about 4 in 5 of the roughly 11 million people in the register. The data stayed within what private companies are allowed to receive, and it did not include names and addresses of people with name-and-address protection.

Officials have not said how the attackers got into the company's systems, whether they have kept or used the data, or who they are. The ministry has told people never to give passwords or other confidential information to anyone who calls or emails, even if the caller seems to know those details.

data breach Denmark third-party access personal data privacy

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.