
Denmark’s government said on Monday that it is investigating a breach of the Central Person Register (CPR), the national population database, affecting about 8.8 million people. According to The Record, the perpetrators used the legitimate access of an unnamed domestic company to pull names, addresses and CPR numbers. A CPR number is a 10-digit identifier that starts with the person’s date of birth and is used for healthcare, banking and government services, and it is roughly comparable to a U.S. Social Security number. The register holds records on around 11 million people, including residents, people who have moved abroad and the deceased.
Officials first spotted irregular activity on Friday, and weekend investigations placed the breach in September. Denmark’s Data Protection Agency, notified on Sunday, described it as a very large number of automated searches aimed at identifying valid CPR numbers. No perpetrator has been named. Research and digitalisation minister Christina Egelund called it “a deeply serious incident,” ordered a broad security review of the system, and extended the country’s digital-security hotline hours (8 a.m. to midnight) for the coming days. Because CPR numbers are meant to last a lifetime, there are fears the risk to those affected could have a long tail; analysts quoted by The Record pointed to the danger of giving private companies direct access to a centralized national database, where one compromised supplier can turn a legitimate connection into a mass exposure.
