The Danish government confirmed Monday that hackers stole the names, addresses, and CPR numbers of roughly 8.8 million registered people from the Central Person Register — the national database of citizens’ identity numbers. According to TechCrunch, it is believed to be the largest data breach in Danish history. The intrusion happened in September, exploited a Danish company’s lawful access to the register, and was only discovered on October 2.
More Records Than Denmark Has People
The number looks impossible until you know how the registry works. Denmark’s population is about 6 million, but the CPR system retains decades of records — 11 million entries in total, including people who have died or emigrated. The attackers walked off with 8.8 million of them: names, home addresses, and the national identity number that ties a person to everything the Danish state knows about them. People registered with name-and-address protection were not exposed, and the company whose access was abused has had that access revoked.
September, October 2, October 5: How It Unfolded
The timeline is short and damning. Sometime in September, attackers used a Danish company’s legitimate CPR access as their doorway — no dramatic exploit needed, just abuse of a working key. The irregular activity was discovered on October 2. On October 5, the government went public. As Cybernews reports, the attack remains unattributed, and officials haven’t said who they suspect. A full month between intrusion and disclosure, and the victims still don’t know who did it.
What a CPR Number Actually Unlocks
A CPR number is Denmark’s equivalent of a Social Security number — the master key for identity in the country. Paired with a name and home address, it’s the raw material for identity fraud: opening accounts, impersonating someone to services and authorities, and building a synthetic identity around a real person who may not discover it for years. For the deceased and emigrated whose records were included, the fraud surface is even stranger — identities that can’t easily defend themselves.
The New Favorite Attack Pattern: Lawful Doors
The detail that should worry every government is how they got in. Nobody broke encryption or zero-dayed the registry. The attackers exploited a company’s lawful access — a trusted third party with a legitimate key. It’s the same pattern behind the biggest national-ID breaches of the past decade: the 2016 Turkish breach that exposed the identity records of nearly 50 million citizens didn’t come through the front gate either. The perimeter is no longer the database. It’s every vendor, contractor, and partner holding a working credential.
Why this matters
The tier-1 coverage gives you the facts: 8.8 million records, discovered October 2, biggest breach in Danish history. What it skips is the pattern — national identity databases keep getting breached through the companies they’re legally required to work with, and each one raises the same unanswered question: how many more lawful doors are still open? If you’re in the register, watch for identity-fraud signs — unexpected mail from banks or agencies, accounts you didn’t open — and consider what the CPR office advises in the coming weeks. The breach is confirmed. The attribution isn’t.
Meanwhile in Tech News: AI executives went under oath at NYC’s AI hearing — accountability, Washington-style, in a different room.


