
Danish authorities have disclosed unauthorized access to personal information belonging to approximately 8.8 million people in the country's Central Person Register (CPR), including names, addresses, and personal identification numbers.
According to an October 5 announcement, the incident involved the misuse of a private Danish company's legitimate access to the register. The CPR administration has revoked the company's access, notified Denmark's data protection authority, Datatilsynet, and is working with specialists and other authorities to investigate.
Administrators first became aware of irregular activity in the CPR system on the evening of Friday, October 2. The activity occurred during September, and investigators established over the weekend that unauthorized parties had accessed information relating to approximately 8.8 million registered individuals.
The CPR is Denmark's central population register and contains approximately 11 million records. These cover living residents, people who have moved abroad, deceased individuals, and other registered persons, meaning the affected figure does not represent 8.8 million current Danish residents.
Company access abused
The authorities said the unauthorized access took place within the categories of information available to private companies through the CPR system.
According to the announcement, Danish law allows companies with a legitimate interest to obtain certain register information about a defined group of people they have already identified individually. Companies must also be entitled to receive that information under applicable data protection rules.
The announcement does not identify the company whose access was abused or explain how unauthorized parties obtained the ability to use it. Investigators have not established who was responsible, and the police investigation remains in its early stages.
A review found that the incident did not expose the names and addresses of people who had registered for name and address protection. The announcement does not state whether those individuals' CPR numbers were also excluded from the unauthorized access.
Authorities cautioned that the reported details could be revised as investigators establish the full sequence and scope of the incident.
Security review and public warning
Research, Education and Digitalization Minister Christina Egelund described the incident as deeply serious and said she had informed Parliament's Business and Digitalization Committee.
The minister has requested a thorough security review of the CPR system. Authorities have also introduced measures intended to prevent similar incidents, although the announcement does not detail those changes. The review will help determine whether further action is needed.
The public warning focuses on attempts to obtain passwords or other confidential information by telephone, email, or similar channels. Authorities stressed that people should not disclose this information, even if the caller appears to know their name, address, and CPR number.







Leave a Reply