Denmark’s Ministry of Research, Education and Digitalization has announced a major cybersecurity breach in the country’s Civil Registration System (CPR).
Operative Information Center-OMM reports that, according to an official statement, unidentified individuals accessed the database by abusing a Danish company’s legitimate access to the CPR system.
As a result, the names, home addresses and personal identification (CPR) numbers of about 8.8 million people registered in the system were obtained by unauthorized parties.
CPR management immediately blocked the company’s access to the system, and a wide-ranging investigation into the incident has begun.
Denmark’s Minister of Research, Education and Digitalization, Christina Egelund, described the incident as an “extremely serious security crisis.” She said authorities are investigating its origins alongside relevant law enforcement and cybersecurity agencies, and have begun introducing additional safeguards to protect personal data and prevent similar incidents. She also urged residents to remain vigilant.
According to Danish media, the country has a population of more than 6 million, while the CPR system, which serves as a personal data register, contains records for about 11 million people, including deceased individuals and people living abroad. Civil registration systems are used to maintain official records of residents and support the delivery of public services, making the protection of their data a key security concern.