Denmark’s largest data breach exposes 8 million citizen records from national database
Denmark’s Central Person Register (CPR), a critical national identity database, has suffered a massive data breach affecting 8 million citizens and residents. The incident, discovered on October 2, exposed sensitive information, including social security numbers and addresses, after hackers exploited a Danish company’s lawful access to the system. Authorities are calling it the country’s largest-ever cybersecurity breach.
Editor, Lazyfounder

Denmark’s Central Person Register (CPR), a critical national identity database, has suffered a massive data breach affecting 8 million citizens and residents. The incident, discovered on October 2, exposed sensitive information, including social security numbers and addresses, after hackers exploited a Danish company’s lawful access to the system. Authorities are calling it the country’s largest-ever cybersecurity breach.
30 SEC SUMMARY
- Denmark’s Central Person Register (CPR), a national identity database, suffered a major data breach affecting 8 million citizens and residents.
- Hackers stole sensitive information, including names, addresses, and social security numbers, by exploiting a Danish company’s lawful access to the CPR system.
- The breach occurred in September 2026 but was discovered on October 2, marking Denmark’s largest-ever data breach.
- The incident highlights growing risks to national identity databases, following similar attacks in Turkey and India.
- Danish authorities are treating the breach as a "serious incident" with potential long-term consequences.
TABLE OF CONTENTS
- Breach exposes sensitive data of 8 million
- How the breach unfolded
- A global trend in identity database breaches
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- Denmark confirmed a data breach affecting 8 million citizens and residents, exposing names, addresses, and social security numbers.
- The breach occurred in September 2026 but was discovered on October 2, with hackers exploiting a Danish company’s lawful access to the CPR system.
- The incident is the largest data breach in Denmark’s history, surpassing previous cybersecurity incidents.
- Similar breaches have targeted national identity databases in Turkey and India, raising concerns about global cybersecurity risks.
Breach exposes sensitive data of 8 million
The Danish government confirmed a major data breach of its Central Person Register (CPR), a national database containing sensitive information about citizens and residents. According to TechCrunch, the breach exposed records of approximately 8 million people, including names, addresses, and Danish social security numbers. The database also includes records of deceased individuals and citizens living abroad, which explains why the number of affected records exceeds Denmark’s current population of 6 million.
How the breach unfolded
The breach occurred in September 2026 but was only discovered on October 2, according to reports. Danish minister Christina Egelund described the incident as a "serious incident," though the full extent of the damage remains under investigation. The unauthorized access was reportedly obtained by exploiting a Danish company’s lawful permission to search the CPR system for information. TechCrunch reported that some companies in Denmark have legitimate access to the CPR for verifying citizen data with the government.
A global trend in identity database breaches
The breach is being treated as the largest in Denmark’s history, surpassing all previous cybersecurity incidents in scale. It follows a pattern of attacks targeting national identity databases worldwide. For example, in 2016, a breach exposed the records of millions of Turkish citizens, while India’s Aadhaar database has faced multiple exposures of national ID cards and personal data in recent years.
What this means
Lazyfounder analysis — our interpretation, not reported fact.
This breach underscores the vulnerabilities inherent in centralized national identity systems, even in countries with advanced digital infrastructures. For founders and operators, especially those in cybersecurity or identity verification, the incident is a stark reminder of the risks posed by third-party access to sensitive databases.
While Denmark’s response will likely include stricter access controls and audits, the damage—identity theft, fraud, and erosion of public trust—may take years to mitigate. Startups in this space should note the growing scrutiny on how companies handle lawful access to government databases and consider proactive measures to secure their own systems against similar exploits. The incident also reinforces the need for decentralized or privacy-preserving alternatives to monolithic identity databases.
Key takeaways
- The breach exposed records of 8 million people, including names, addresses, and social security numbers, from Denmark’s Central Person Register.
- Hackers gained access by abusing a Danish company’s legitimate permissions to query the CPR system.
- The breach is Denmark’s largest-ever cybersecurity incident, discovered weeks after it occurred.
- Similar attacks on national identity databases have occurred in Turkey and India, signaling a global trend.
- The incident raises questions about the security of third-party access to sensitive government databases.
FAQ
What information was stolen in the Danish CPR breach?
The breach exposed names, addresses, Danish social security numbers, and other sensitive personal information stored in the Central Person Register.
How did hackers gain access to the CPR system?
According to reports, hackers exploited a Danish company’s lawful permission to search for information in the CPR system, abusing their access to steal data.
Why does the breach affect 8 million people if Denmark’s population is 6 million?
The CPR database includes records of deceased individuals, citizens living abroad, and other entries, totaling around 11 million records. The breach affected approximately 8 million of these.
Has Denmark experienced a breach of this scale before?
No, Danish authorities have described this as the largest data breach in the country’s history.
Are similar breaches common in other countries?
Yes, national identity databases in other countries, such as Turkey and India, have also been targeted by cyberattacks in recent years.
Related on Lazyfounder
Sources
- TechCrunch · 2026-10-05
Hackers steal 8 million citizens’ records from Danish government database
This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.
About the author
Editor, Lazyfounder
Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.
More stories by Tarun MottliaGet the LazyFounder Brief
Startup, funding and AI news in a five-minute read. Join the early-access list.


