INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Denmark's Central Person Register Experiences Data Breach Incident

| 2026-10-06 09:38 HIGH LOW DATA BREACH
Executive Summary
AI-generated
On October 6, 2026, Denmark's Central Person Register (CPR) notified approximately 8.8 million people that their personal information was stolen in a data breach. The incident occurred when hackers exploited the lawful access granted to CPR by Danish companies under the country's Data Protection Regulation and Data Protection Act. Established in 1968, CPR contains information on about 11 million individuals, including residents, emigrants, and deceased individuals. After discovering the breach, CPR terminated the private company's access, notified the Danish Data Protection Agency, and launched an investigation with authorities. The population register urges individuals to be wary of unsolicited communication requesting personal information, passwords, and other sensitive data, while also reviewing its security policies to prevent similar incidents.
Technical Mitigations AI-generated
• Block or hunt for suspicious login attempts from unknown IP addresses. • Review and update the Danish company's lawful access to the CPR system, ensuring that all necessary permissions are revoked after the incident. • Implement additional security measures on the CPR system, such as multi-factor authentication (MFA) for sensitive data requests.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORDICS NORDICS
Incident Timeline
‎2026/10/06
Hackers accessed the names, addresses, and CPR numbers of approximately 8.8 million registered individuals through a Danish company's lawful access to Denmark’s Central Person Register.
organisation Data Breach
organisation Denmark’s Central Person Register
organisation CPR
organisation Pentagon Personnel Agency Data
organisation Gyazo Data Breach
data_breach 400,000 Beneficiary Records
data_breach 23 Beneficiary Records
organisation Social Security
organisation Texas Healthcare Firms
organisation the Danish Data Protection Agency
Tactical Metrics
Metrics
data_breach
400,000
Beneficiary Records
Metrics
data_breach
23,000,000
Beneficiary Records
Intelligence Sources