Abstract:
The Danish government recently confirmed that the country’s central citizen information database has been attacked by a cyber attack and most of the data has been stolen by hackers. The incident affected approximately 8 million Danish citizens and residents, including not only those living overseas, but also deceased persons. It is considered one of the largest personal data breaches in Danish history.

Christina Egglund, Denmark’s Minister of Science, Innovation and Higher Education, said in a statement that the intrusion into the Central Person Register (CPR) was a “serious incident.” The attackers obtained and stole a large amount of data including names, addresses, Danish social security numbers, and other personal information.
CPR is the core database used by the Danish government to manage citizen information, recording citizen identity information and personal identification numbers issued by the government. These identification numbers are widely used for paying taxes, accessing public services, and for various types of official identification. Although Denmark's current population is about 6 million, the database holds historical records for about 11 million people, some of which goes back decades.
The Danish government did not reveal the identity of those behind the attack. According to official disclosures, the intrusion occurred in September 2026, but was not discovered until October 2. The government said the attackers achieved unauthorized access by "abusing legally obtained access to the CPR system of a Danish company." In Denmark, some companies are allowed to access the CPR system to verify personal identity information and conduct related business.
The official has not announced more technical details, nor has it stated how much data the attacker has obtained. However, the government confirmed that unauthorized access resulted in the export and theft of large amounts of citizen data from the system.
This incident is considered to be one of the most serious data breaches in Denmark's history, and it has once again highlighted the cybersecurity risks faced by the national identity database. In recent years, the citizen identity information systems of many countries have been targeted. For example, in 2016, a major leak of information involving millions of citizens occurred in Turkey; India's national identity authentication system "Aadhaar" has also experienced multiple leaks of ID numbers and related personal information.
As more and more countries integrate identity authentication, taxation and public services into unified digital platforms, large-scale citizen databases have become a key target for cybercriminals. The intrusion of the Danish CPR system is expected to prompt the government to re-examine the access rights management and data security protection mechanisms of critical identity infrastructure.
Comments