Hackers accessed Denmark's Central Person Register in September, stealing personal data of approximately 8 million citizens and residents. The breach was uncovered on October 2, with authorities indicating that the attack involved exploiting a Danish company's authorized access to the system. The database contains sensitive information including names, addresses, and social security numbers.
yro.slashdot.org
· 2026-10-05
Denmark's government confirmed that hackers stole most of the contents of its Central Person Register, a database holding identity data on roughly 11 million people including the deceased and those living abroad. Minister Christina Egelund called it a "serious incident," saying attackers gained access by abusing a private Danish company's legitimate credentials to query the system. The breach occurred in September but wasn't discovered until October 2, and authorities have not named a suspect.
techcrunch.com
· 2026-10-05
Denmark's Central Population Register said attackers exploited a private company's legitimate system access to brute-force valid CPR numbers and extract names, addresses and identification data, affecting roughly 8.8 million of the registry's 11 million entries, including residents, émigrés and deceased individuals. The breach occurred in September 2026 but was discovered October 2, with the company's access now blocked and police investigating.
bleepingcomputer.com
· 2026-10-05
Denmark's Central Person Register (CPR) confirmed that unauthorized parties exploited a private company's legitimate access to the system to obtain names, addresses, CPR numbers and other personal data belonging to roughly 8.8 million registered citizens. Records of citizens who had opted for name and address protection were not affected. Authorities have cut off the company's access, reported the incident to the Danish Data Protection Agency, and police are investigating alongside other relevant agencies.
cpr.dk
· 2026-10-05
The Technical University of Denmark disclosed that attackers used compromised credentials to access DTUBasen, its identity and access management system, downloading over two decades of user data. The system holds records for roughly 40,000 active users and 160,000 former users, including Danish civil registration numbers, addresses, profile pictures and next-of-kin contact details. DTU says it cannot yet determine exactly what data was taken or how many people are affected.
bleepingcomputer.com
· 2026-10-03