Denmark’s Civil Registry Warns of Massive Data Leak Impacting Nearly 9 Million Citizens
Denmark’s Central Population Register (CPR) announced that a security breach has potentially exposed the personal details of roughly 8.8 million individuals registered in the national database, the largest data incident of its kind in the country’s recent history.
The CPR, which serves as the backbone for a wide range of public services—from tax administration to healthcare—stores basic identifiers such as names, dates of birth, and unique civil registration numbers. While the exact scope of the compromised data has not been fully disclosed, officials confirmed that the breach could affect virtually the entire resident population, given the register’s comprehensive coverage.
Authorities have not identified the source of the intrusion, but they have emphasized that the breach appears to stem from unauthorized access to the registry’s digital infrastructure. The incident was first reported by cybersecurity outlet BleepingComputer, prompting the Danish Data Protection Agency to launch a formal investigation under the EU’s General Data Protection Regulation (GDPR) framework.
Data protection experts warn that the exposure of CPR numbers could facilitate identity theft, fraud, and unauthorized profiling. In Denmark, the civil registration number is a key credential used across banking, social services, and employment verification, meaning that malicious actors could potentially exploit the data for a range of illicit activities.
In response, the government has urged all affected individuals to monitor their financial accounts and to be vigilant for suspicious communications. It also announced a series of remedial measures, including a review of access controls, accelerated rollout of multi‑factor authentication for internal users, and an outreach program to inform citizens about steps to protect their identities.
The breach underscores growing concerns about the security of centralized state-held databases in an era of increasingly sophisticated cyber threats. As investigations continue, lawmakers are expected to debate whether additional legislative safeguards are needed to reinforce the resilience of critical public registries and to ensure that similar incidents are mitigated in the future.
Comments (0)
Be the first to comment.
Join the discussion