A cyberattack involving Denmark’s central civil registration system has exposed data linked to around 8.8 million registered individuals. According to the authorities, the attackers did not breach the government system directly but instead abused the legitimate access credentials of a private company. Officials are now warning of an increased risk of phishing, social engineering and identity-related fraud.
Denmark is investigating one of the most significant data security incidents the country has faced in recent years. Unauthorised actors gained access to information held in the Central Person Register, known as CPR (Det Centrale Personregister), which forms a core component of Denmark’s administrative infrastructure.
According to the Ministry of Higher Education and Science, the compromised data relates to approximately 8.8 million registered individuals.
The information accessed includes names, addresses and Danish CPR numbers, which are widely used for personal identification in dealings with public authorities and private-sector organisations. The affected records include data relating not only to current residents, but also to people who have moved abroad and individuals who have died.
Minister Christina Engelund described the incident as “extremely serious”. The authority responsible for the register was alerted in early October to unusual access activity that had reportedly taken place during September. Investigations into the precise scope, method and circumstances of the incident are continuing.
Legitimate corporate access exploited
From a cybersecurity perspective, the route of compromise is particularly significant. Based on the information released so far, the attackers did not directly penetrate the central government database. Instead, they appear to have exploited authorised access belonging to a Danish private-sector organisation.
Companies may, under defined legal conditions, be granted access to selected information held in the CPR system where a legitimate purpose can be demonstrated. The access involved in the incident has since been blocked.
The case highlights a recurring challenge in the protection of sensitive public-sector data: even where core infrastructure itself is well secured, trusted external access can create additional exposure.
Compromised business accounts, third-party systems or legitimate user credentials may effectively bypass security controls designed to protect the central platform itself. As a result, identity and access management, continuous monitoring and third-party risk controls are becoming increasingly important elements of public-sector cyber resilience.
The CPR database contains records relating to around eleven million people in total. In addition to Denmark’s population of roughly six million, the register includes former residents and deceased individuals. According to the authorities, people whose names and addresses are subject to enhanced confidentiality protections were not affected.
Authorities warn of phishing and social engineering
Danish authorities have also warned that the stolen information could be used in subsequent fraud campaigns.
Names, addresses and CPR numbers can make phishing emails, fraudulent phone calls and other forms of social engineering appear considerably more credible. Attackers may use genuine personal information to impersonate government agencies, banks or established service providers.
Citizens have therefore been advised not to disclose passwords, login credentials or other confidential information simply because a caller or sender appears to know personal details about them.
The incident illustrates a broader security lesson that extends well beyond Denmark. Protecting sensitive public-sector data is no longer solely a matter of defending the central database. Security must also cover every authorised access route around it — including external organisations, privileged accounts, service providers and trusted interfaces.
In highly connected digital administrations, the weakest point may not be the core system itself, but the legitimate pathway leading into it.



