Denmark Data Breach: Hackers Steal 8 Million Citizen Records From Government Database

Denmark Data Breach: Hackers Steal 8 Million Citizen Records From Government Database

TL;DR

  • Denmark has confirmed hackers stole names, addresses and CPR ID numbers for 8 million people from a central government database maintained by an external IT supplier.
  • The total exceeds Denmark's 5.9 million population because the database included expats, immigrants, and deceased citizens whose records are retained for years.
  • Officials say MitID logins and passwords were not taken, but warn of high identity fraud risk and urge citizens to watch for phishing, monitor their CPR usage, and secure Digital Post.

A Breach Bigger Than The Country Itself

Denmark is dealing with one of the largest government data breaches in its history after officials confirmed over the weekend that attackers accessed a central civil registry containing personal data on 8 million people.

That figure is staggering because Denmark's current population is only about 5.9 million. The Danish Agency for Digital Government said the incident exposed names, current and former addresses, and CPR numbers - the 10-digit state-issued ID numbers used for everything from healthcare and taxes to banking and voting.

In a statement released October 3, the agency said there is no evidence so far that the stolen data has been published or misused, but it warned that the combination of data taken creates a serious, long-term risk of identity theft and fraud.

What Was Stolen, And What Wasn't

According to the government's initial disclosure, the attackers obtained three core data fields: Names, residential addresses including historical addresses, and CPR numbers.

Officials were quick to stress what was not included in this breach. No MitID credentials, passwords, banking details, health records, or Digital Post contents were taken. Biometric data and financial account numbers were also not part of the compromised database.

But cybersecurity experts say that distinction offers limited comfort. In Denmark, a CPR number functions much like a U.S. Social Security number, only more powerful. Paired with a name and address, it can be used to attempt to open accounts, take out loans, order goods in someone else's name, or craft highly convincing phishing attacks.

How Did Hackers Get In

The breach did not hit the government's core systems directly. Instead, investigators say attackers compromised systems operated by an external IT supplier that manages and hosts parts of the civil registration infrastructure.

Danish authorities have not yet publicly named the threat actor or the exact vulnerability exploited, but said the unauthorized access took place over an extended period before being detected during a security review in late September 2026. The supplier's access has since been shut down and the vulnerability closed.

The case follows a pattern seen across Europe in recent years, where state agencies reliant on a small number of large contractors become vulnerable through their supply chain. Once inside the supplier's environment, the attackers were able to query and exfiltrate large volumes of registry data without triggering immediate alarms.

Police, the Centre for Cyber Security, and the Danish Data Protection Agency are now investigating. Officials said they are also auditing other government suppliers for similar weaknesses.

Why 8 Million Victims In A Country Of 5.9 Million

The math that confused many people over the weekend actually points to how Denmark's CPR system works.

The Civil Registration System, known as CPR, does not just cover people living in Denmark today. It retains records for:

  1. Current residents, including Danish citizens and foreign nationals with residence permits.
  2. Danes living abroad as expats, many of whom keep their CPR numbers for tax, pension and consular purposes.
  3. Former residents, including immigrants who have left Denmark but whose records are archived.
  4. Deceased persons, whose CPR records are typically kept for at least 10 years after death for legal, inheritance and statistical reasons, and in many cases much longer in backups.

Because of that long retention, a full copy or large extract of the registry can easily exceed the living population by several million. That also means families of deceased citizens may need to be vigilant against fraudsters attempting to misuse a dead relative's identity to claim benefits or evade checks.

Why CPR Numbers Are So Sensitive

Unlike a password, you cannot simply change your CPR number. In Denmark, it is assigned at birth or upon immigration and follows you for life. Changes are granted only in exceptional cases involving serious threats or errors.

That permanence is what makes this breach particularly damaging. Even if the data is never posted publicly, criminals can hold onto it for years and combine it with other leaks, such as phone numbers and emails from previous commercial breaches, to build complete identity profiles.

The Danish government has acknowledged that risk and said it will not issue new CPR numbers en masse, a move officials say would disrupt the entire welfare and banking system.

What Victims Should Do Right Now

Authorities say there is no need to show up at Borgerservice in person, but everyone with a Danish CPR number should assume they are affected and take precautions.

First, be extremely skeptical of contact claiming to be from the government, bank, or police. Do not click links in unexpected SMS messages, emails or Digital Post notifications asking you to verify your CPR or MitID. Real Danish authorities will never ask for your MitID password or code via phone or email.

Second, monitor your identity. Check your credit status with Experian and Debitor Registret, review your tax folder on Skat.dk for unfamiliar activity, and activate notifications in your online bank and MitID app for new logins or credit agreements. Parents and relatives should also watch for misuse of CPR numbers belonging to children and deceased family members.

Third, secure your digital accounts. Update your MitID app, turn on extra alerts, use strong unique passwords with two-factor authentication where possible, and consider requesting a credit block or payment warning, known as betalingsadvarsel, to make it harder for criminals to take loans in your name.

The government said it will send official guidance via Digital Post and has set up a dedicated hotline and information page. Victims who suspect fraud should report it to police and contact their bank immediately.

What Happens Next

Denmark's Minister for Digitalisation said the government will tighten security requirements for all state IT suppliers, mandate faster breach reporting, and review how long historical CPR data needs to be stored in directly accessible systems.

The Data Protection Agency is expected to decide whether fines or further action against the supplier are warranted, while parliament has called for an emergency briefing this week.

For now, officials are urging calm but not complacency. Unlike a credit card that can be cancelled, the 8 million CPR numbers stolen in this attack will remain valid for decades, meaning the fallout from this breach could linger far longer than the news cycle.


AndroGuider Team
Articles written by the AndroGuider team. We try to make them thorough and informational while being easy to read.
Denmark Data Breach: Hackers Steal 8 Million Citizen Records From Government Database Denmark Data Breach: Hackers Steal 8 Million Citizen Records From Government Database Reviewed by Randeotten on 10/05/2026 11:53:00 PM
Subscribe To Us

Get All The Latest Updates Delivered Straight To Your Inbox For Free!





Powered by Blogger.