A significant data breach has compromised the personal information of approximately 8.8 million individuals listed in Denmark's national population register, according to an announcement from the country's digitalization ministry on October 5. The breach occurred when unauthorized parties exploited a private Danish company's legitimate access to the Central Person Register (CPR), gaining access to names, addresses, and personal identification numbers of both living and deceased individuals. The ministry has advised citizens to be vigilant and not to share passwords or confidential information with unsolicited callers or email senders.

In response to the breach, the register's administration has revoked the company’s access and reported the incident to Datatilsynet, Denmark's data protection authority. Law enforcement is currently investigating the matter. Datatilsynet disclosed that a large volume of automated lookups targeted valid CPR numbers over a ten-day period in September. An employee flagged the suspicious activity on October 2, leading to the discovery of the breach's scope.

The breach affects a broad spectrum of individuals, including current residents, people who have moved abroad, and deceased individuals. While the breach included data that companies are typically authorized to access, it did not involve individuals with name-and-address protection. The ministry's statement did not clarify whether affected individuals would be individually notified.

Authorities have emphasized the importance of safeguarding personal data and directed individuals to resources such as sikkerdigital.dk for fraud prevention advice. Furthermore, a Cyberhotline has been established to assist citizens in implementing security measures. In the wake of this breach, Minister Christina Egelund has called for a comprehensive security review of the register to prevent future incidents. Datatilsynet is conducting an investigation to determine the breach's causes and to assign responsibility for the mishandling of personal data.