Denmark CPR breach exposes records of 8.8M people
🔒 The Danish Central Population Register (CPR) disclosed a data breach that exposed personal information for approximately 8.8 million registered individuals, including residents, expatriates, and deceased persons. Threat actors abused a private company's legitimate access and used brute-force enumeration of CPR numbers to extract names, addresses, dates of birth, marital status, and CPR identification numbers. The breach occurred in September 2026, was discovered on October 2, and affected about 80% of records held in the CPR system. Authorities have blocked the third party's access, launched a police investigation, and enacted extra security measures while urging citizens to remain vigilant.
