TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
Denmark’s Central Person Register says unauthorized users misused a Danish company’s legitimate access to obtain personal data on about 8.8 million registered people. The review found that names and addresses of people with name and address protection were not included; authorities have stopped the company’s access and are investigating.
Denmark’s Central Person Register (CPR) has disclosed unauthorized access to personal data for about 8.8 million registered people, after intruders misused a Danish company’s legitimate permission to search the system. The register administration says it has stopped the company’s access, while police and relevant authorities investigate how the access occurred and what happened to the information.
The CPR administration said the information accessed included names, addresses and CPR numbers, Denmark’s personal identification numbers. Its initial review found that the unauthorized access did not include the names and addresses of people who had registered for name and address protection. The announcement does not specify whether other information relating to those protected people was accessed.
According to the register, the incident involved abuse of a Danish company’s lawful access to search the CPR system. The administration has terminated the company’s access and said it is working with specialists and public authorities to map the course of events. It has reported the matter to the Danish Data Protection Agency, and police are investigating in cooperation with relevant authorities.
The public notice does not identify the company or give a date range for the access. It also does not state whether the information was copied, published, sold or used to target individuals. Those points remain subject to the ongoing investigation, so the confirmed scope currently rests on the administration’s account of its review.
Risks From Exposed CPR Details
The scale of the incident means that personal information tied to millions of Danish residents may have been accessed through a system used to identify people in public administration and other settings. Names, addresses and CPR numbers can make records more identifiable and could create risks of impersonation, targeted fraud or unwanted contact. The notice does not say that any of these harms have occurred, and it gives no evidence about how the information has been handled since access took place.
The case also raises questions about how organizations with legitimate access to sensitive government systems are monitored and how misuse is detected. The CPR administration says it has shut off the company’s access, but has not yet described the technical or organizational measures involved in the misuse. The investigation’s findings should help establish whether the incident arose from compromised credentials, misuse by an authorized user, or another route; the available announcement does not determine which explanation applies.
People whose details may be involved will need clearer information about the specific data affected and any practical steps they should take. The current notice confirms a broad exposure but does not provide individual notifications, advice on monitoring accounts, or a dedicated support channel. Those details may follow as the authorities clarify the incident.
As an affiliate, we earn on qualifying purchases.
How CPR Access Was Misused
The CPR is Denmark’s central population register. The incident notice describes the access path as misuse of a Danish company’s authorized ability to search the register, rather than claiming that attackers broke directly into the register’s underlying systems. It does not explain the company’s role, the terms of its access, or how searches were carried out.
The administration says its review identified the approximate number of registered people whose data was accessed and one specific exclusion: protected names and addresses were not part of the unauthorized access. It has not published a technical incident timeline, details about detection, or an account of the safeguards that failed. These facts will matter in assessing both the extent of exposure and whether other parties or systems were affected.
The register administration has referred the case to the Danish Data Protection Agency, and police are investigating with relevant authorities. The notice points readers to the Ministry of Higher Education and Science for further information. No findings from the police investigation or data protection review are included in the material available here.
As an affiliate, we earn on qualifying purchases.
Scope and Use Still Under Review
The register’s notice does not identify the company, specify when the unauthorized access began or ended, or explain how many searches were made. It gives an approximate total of 8.8 million registered people, but does not publish a breakdown of records or the method used to calculate that figure.
It is also unclear whether the data was downloaded, retained, shared or used for fraud or other purposes. The administration’s review says protected names and addresses were not included, but does not say whether other details about people with that protection were accessed. The investigation is ongoing, and no final findings from police or the data protection authority are included in the announcement.
As an affiliate, we earn on qualifying purchases.
The CPR administration says it is working with specialists and public authorities to map the incident. Police are investigating alongside relevant agencies, and the administration has notified the Danish Data Protection Agency. Their work may clarify the access timeline, the way the company’s permissions were misused and the handling of any information obtained.
Further official updates are needed to establish whether affected people will receive individual notice, what protective steps they should take and whether the company or other parties face additional action. The source notice directs readers to the Ministry of Higher Education and Science for further information, but does not give a timetable for findings or follow-up announcements.
As an affiliate, we earn on qualifying purchases.
Key Questions
What information was accessed?
The CPR administration says unauthorized users obtained names, addresses and CPR numbers through misuse of a Danish company’s legitimate access. The notice does not provide a complete list of data fields.
How many people were affected?
The administration reports that data relating to about 8.8 million people registered in the CPR was accessed. It has not published a detailed breakdown or the calculation behind the approximate figure.
Were protected names and addresses exposed?
The administration’s review says the unauthorized access did not include the names and addresses of people registered for name and address protection. It has not specified whether other information about those people was accessed.
Who is investigating the incident?
The CPR administration reported the case to the Danish Data Protection Agency. Police are investigating in cooperation with relevant authorities, while specialists help the administration map what happened.
Has the data been used or shared?
The public notice does not say whether the information was copied, shared, published or used. That remains among the unresolved questions in the ongoing investigation.
Source: hn
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
