INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Denmark population registry data breached exposing 8.8 million records

| 2026-10-05 15:21 HIGH LOW DATA BREACH
Executive Summary
AI-generated
Denmark's Central Population Register (CPR) experienced a data breach in September 2026, which was discovered on October 2 and affected approximately 8.8 million registered individuals, including those living in Denmark, abroad, and deceased people. The private Danish company that had legitimate access to the registry system misused it to obtain personal information, including names, addresses, CPR numbers, and other details. Threat actors used a brute-forcing method to enumerate valid CPR numbers before extracting related data from each entry. A dedicated "cyber hotline" has been set up for potentially affected individuals, while additional security measures have been implemented to prevent similar incidents on the CPR system. The incident is being investigated by police, and Minister Christina Egelund has informed Parliament's Business and Digitalization Committee about it.
Technical Mitigations AI-generated
• Block brute-forcing attempts to enumerate valid CPR numbers. • Implement additional security measures, such as password protection and secure authentication protocols, for the Central Population Register system. • Monitor for unsolicited communications from potentially affected individuals.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORDICS NORDICS
Incident Timeline
‎September 2026
The Denmark population registry data breach, affecting 8.8 million people, was discovered on October 2 by CPR administration after the security incident occurred in September 2026.
organisation Egelund
organisation BleepingComputer
organisation NFL
organisation CHANEL
‎October 2
Threat actors exploited vulnerabilities to breach the Denmark population registry data, affecting approximately 8.8 million people.
‎2026/10/05
Threat actors misused a private Danish company's legitimate access to the Denmark population registry system to obtain sensitive personal data.
target_region Denmark
‎2026/10/05
Threat actors used brute-forcing to enumerate valid CPR numbers, then extracted related data from each entry.
organisation Central Population Register
organisation CPR
organisation Danish Data Protection Agency
Intelligence Sources