Denmark Reveals Massive Data Breach Impacting Nearly 9 Million Citizens
Denmark's government confirmed that a large‑scale cybersecurity breach has compromised the Central Person Register, exposing personal details of approximately 8.8 million registered residents.
The Central Person Register, known as the CPR system, serves as the backbone of the country's public administration, linking citizens to health care, tax, and social services. Access to its data is tightly controlled, making the breach especially concerning for both officials and the public.
According to the ministry, the unauthorized intrusion gave attackers access to names, home addresses, CPR numbers and other identifiers tied to each individual. While the full scope of the extracted information has not been disclosed, the combination of identifiers could facilitate identity theft or fraud if misused.
Authorities say the breach was detected during routine security monitoring earlier this week. The Danish Security and Intelligence Service, together with the national police cyber unit, have launched a forensic investigation to determine how the attackers bypassed existing safeguards and to identify the perpetrators.
In response, the government has urged citizens to remain vigilant, advising them to watch for suspicious communications, verify the authenticity of any requests for personal data, and report irregular activity to the newly established hotline.
To mitigate potential harm, the state is offering free credit‑monitoring services for affected individuals and is reviewing security protocols across all public registers. Officials also indicated that they will work closely with the European Data Protection Board to ensure compliance with EU privacy regulations.
The incident arrives amid a wave of high‑profile cyberattacks targeting governmental databases across Europe, highlighting the growing challenge of protecting large‑scale personal data sets from increasingly sophisticated threat actors.
While the investigation remains ongoing, officials emphasized that no evidence currently suggests the data has been publicly posted or sold. They pledged to keep the public updated as more details become available and to pursue legal action against any parties found responsible.
The breach underscores the importance of robust cybersecurity measures for national registries and serves as a reminder that even well‑protected systems can be vulnerable to determined attacks.
Comments (0)
Be the first to comment.
Join the discussion