Trending: On-device modelsSearch
iHeartGeek
iTECH

Denmark's CPR register breach exposes 8.8 million people

Unauthorised parties used a Danish company's lawful access to the national register to copy the names, addresses and CPR numbers of 8.8 million people.

A long aisle between rows of wooden index-card drawers in a records hall, photographed in one-point perspective under strip lighting

Denmark's government has confirmed that unauthorised parties copied personal data on around 8.8 million people out of the Central Person Register, the state database that issues and holds the CPR number every Danish resident uses for tax, healthcare and public services.

What was taken

The data taken includes names, addresses and CPR numbers, according to the Ministry of Research, Education and Digitalisation, which oversees the register. The 8.8 million figure covers living residents, people who have emigrated and the deceased. Reuters-wire copy carried by The Copenhagen Post puts the number of affected registered individuals at around 8.8 million, while TechCrunch reported the total as some 8 million.

The register itself reaches further than a list of names. The ministry says the CPR system holds records on roughly 11 million people, against a living population of about 6 million, and that entries can also carry marital status, birth registration details, family relationships, affiliation with the Church of Denmark and information about legal incapacitation. The ministry has not said which of those extra fields were copied in each case.

How the register was reached

The breach did not require anyone to break into the register from outside. The ministry said the intruders abused a Danish company's lawful ability to search the CPR system, and that the company's access has since been blocked. Some Danish companies are allowed to query the register to verify identity details against government records, which is exactly the permission that was used here.

The unauthorised access took place during September, and the CPR administration became aware of it on the evening of Friday 2 October. The government has not named the party behind the breach. TechCrunch reports that it is thought to be the largest data breach in Danish history.

The political response

Christina Egelund, the minister for research, education and digitalisation, called it a deeply serious incident. “It is a deeply serious incident, which I have therefore also briefed the Folketing's Business and Digitalisation Committee about,” she said. “Together with all relevant authorities, we are in the process of mapping the full extent of the incident.”

Our opinion

The part of this that should worry every other country running a single national identifier is not the theft, it is the door. Nobody had to forge anything, defeat encryption or bribe an administrator; the intruders simply used a credential Denmark had already decided to hand out to private companies, because verifying identity through the register is cheaper than building a second system. Every legitimate query route is also a copy route, and the register was never designed on the assumption that one of those routes would be turned into a bulk export. The numbers make the concentration of risk plain: a register holding 11 million records for a country of 6 million is not a database any more, it is a permanent archive of the dead and the departed sitting behind the same access-control list as the living. Blocking the company's access is containment, not repair. The harder questions are the ones nobody in Copenhagen can answer quickly, because a CPR number cannot practically be reissued the way a password can: it is embedded in tax records, bank files, medical histories and every contract a person has ever signed. Danish authorities now have to decide whether the right response is to rebuild the trust model around the register or to accept that the number is compromised forever and start building identity checks that do not depend on it.