Denmark Just Suffered the Biggest Data Breach in Its History

Denmark's government confirmed hackers abused a private company's lawful access to the CPR system, stealing names, addresses, and national ID numbers for about 8 million people in the country's biggest breach ever.

Get a summary in:
Digital lock representing a cybersecurity data breach
Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google
AAAdmin AlexWriter
MAM.AliFact-Checker

Published: October 5, 2026 · Last updated: October 5, 2026

TL;DR: Denmark’s government confirmed hackers abused a private company’s lawful access to the CPR system, the country’s central database of citizen identity data, stealing names, addresses, and national ID numbers for about 8 million people in what officials are calling the biggest breach in Danish history.

Denmark’s government just confirmed its biggest data breach ever, and the attackers didn’t need to break into anything the government built. They walked in through a door the government handed to a private company.

Server racks holding government data infrastructure

The target was the Central Person Register, known in Denmark as the CPR system. It’s the database that assigns every resident a personal identification number and ties it to their name, address, and a long list of other records used across taxes, banking, healthcare, and government services. Denmark’s population is around 6 million people, but the CPR system itself holds records on roughly 11 million, a figure padded out by decades of historical data, people who’ve moved abroad, and the deceased.

According to the Danish government’s own disclosure, reported first by TechCrunch, the breach exposed names, addresses, CPR numbers, and other information for about 8 million people. The intrusion happened in September and wasn’t discovered until October 2, a gap of several weeks during which the stolen data was presumably already out the door.

Here’s the part that should worry security teams more than the headline number. The government hasn’t said a hacking group broke into the CPR system directly. Instead, officials say the access came from abusing a Danish company’s lawful access to search the database. Companies in Denmark routinely get CPR access to verify identities for things like loan applications and account openings, which means the breach likely didn’t require defeating a single government firewall. It required getting inside, or compromising, one of the many businesses the government already trusts with a key.

Danish minister Christina Egelund called it a “serious incident,” which is about as far as officials have gone publicly. The government hasn’t named the company whose access was abused, hasn’t said whether it was hacked or simply misused its credentials, and hasn’t identified who’s behind the theft. For a breach already being described as the largest in the country’s history, that’s a lot of blanks left unfilled days after discovery.

The practical risk here is bigger than a typical breach because of what a CPR number actually does. It’s not a background identifier like a US Social Security number, mostly kept private and pulled out for specific transactions. Danes use their CPR number constantly, with employers, banks, doctors, landlords, and government offices, which makes it a far more useful piece of data for an identity thief and a far harder one to quietly retire. You can’t just issue 8 million people a new number and call it fixed.

This is also not the first time this year a breach has traced back to third-party access rather than a direct hit on the system holding the sensitive data. Businesses and vendors that get a legitimate door into a government or corporate database keep turning out to be the weakest link, not the systems they’re connecting to. Denmark can harden the CPR system all it wants, but if any of the companies plugged into it have sloppy access controls, the data walks out anyway.

Related: A similar failure mode played out at a Japanese car-sharing service that exposed 6.6 million accounts after an attacker held access for nearly a month, and at IDScan, where more than 150 million driver’s licenses leaked and the company still won’t explain how.

Bottom Line: Denmark didn’t lose this data because its core identity system had a flaw a hacker cracked open. It lost the data because a government built decades of trust into a web of outside companies and never seemed to ask hard enough whether every one of them deserved it.

Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest

Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google