Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5.

They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to give passwords or other confidential information to anyone who calls or emails, even someone who seems to know those details.

The register's administration has stopped the company's access and reported the case to Datatilsynet, Denmark's data protection authority. Police are investigating.

A very large number of automated lookups were made in the register to identify valid personal identification numbers, known as CPR numbers, Datatilsynet said in a notice on October 5. Its account comes from the notification it received from the register a day earlier. It has not yet assessed the case and describes the numbers as allegedly retrieved.

The access lasted about 10 days in September and went through a small Danish company, according to Christina Egelund, the minister responsible for digitalization, who spoke to the news agency Ritzau. An employee of the register's administration noticed the unusual activity on Friday, October 2. Over the weekend, the administration learned how many people's records were involved.

The official statements leave three questions open: how the unauthorized parties gained access to the company's systems, whether they have retained or used the data, and who they are.

Who Is Covered

The 8.8 million figure is the ministry's and is not yet final. It counts registered people: living residents, people who have moved abroad, the dead, and others. The register holds about 11 million people in all, which means the access covered about 4 in 5 of them.

Since 1968, the register has recorded everyone who lives or has lived in Denmark. Denmark's population was just under 6 million at the start of 2025, according to Statistics Denmark.

The access stayed within the data that private companies are allowed to receive, and it did not include the names and addresses of people registered with name-and-address protection, the ministry said. That status, in most cases, prevents the register from disclosing a person's name and address to private companies or individuals.

The ministry's statement does not say whether those people's CPR numbers were reached, or whether anyone will be told individually that they are among the 8.8 million.

What People With a CPR Number Can Do

The ministry points people to the advice site sikkerdigital.dk, which lists four steps to guard against fraud:

  • Be extra alert to unexpected text messages, calls, and emails in which the sender uses details about you.
  • Do not click links in unexpected messages. Go to the official website yourself, or call the sender's main number to check.
  • Never share MitID details, one-time codes, passwords, or card details.
  • Set up a credit warning on borger.dk.

The Cyberhotline for digital security, a government-run help line on +45 33 37 00 37, can help with these steps. It has longer opening hours, from 8 a.m. to midnight, in the days after the announcement.

A credit warning is a marker in the CPR indicating that the holder wants companies to be warned against extending loans or credit in their name. It works as a signal. Companies that choose to receive it are asked to take extra care when checking identity before lending, according to borger.dk, the site where the marker is set.

A new marker is registered at once but can take some days to reach companies' systems. Anyone aged 15 or over can set one, and it can make the holder's loan applications harder to approve until it is removed.

A CPR number helps identify a person but must not be used as the only proof of identity, according to the register's official guidance.

How Companies Get Access to the Register

Under the 2023 text of Denmark's CPR Act, companies can have register data delivered on people they have already identified one by one. A CPR number alone is enough to identify a person for that purpose.

The data they can receive includes a person's current name and address, unless protected, and details such as a death, a move abroad, or a credit warning. The CPR number itself is not on that list.

A CPR number has 10 digits: 6 for the date of birth and 4 serial digits, the last of which is even for women and odd for men.

By The Hacker News's arithmetic, that format allows at most 10,000 possible numbers for each date of birth. Datatilsynet's notice says the lookups were made to identify valid numbers, but neither it nor the ministry's statement says whether they worked through those possibilities.

The register's guidance says companies may only get data on people they already deal with, such as customers or employees. The official statements do not explain how one company's access under those rules came to cover about 4 in 5 people on the register.

Under the act, the ministry responsible for the register sets the terms for company access, including security measures.

Egelund told Ritzau the safeguards around this kind of access had not been solid enough, and agreed that alarms should have gone off given how long it lasted.

What Happens Next

The ministry has begun measures to prevent a repeat, which its statement does not detail, and the minister has requested a full security review of the register.

Datatilsynet is examining what happened, how it could happen, and who is responsible for handling the personal data.

Egelund told Ritzau it was too early to say whether people will need new CPR numbers. The act already allows a new number in special cases where a person's number has been misused.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.