Danish officials said on Monday that someone misused a private company’s access to the national population register to pull the names, addresses and identity numbers of about 8.8 million people.
The register, known as the CPR, holds about 11 million records, so the searches reached roughly four in five of them, according to the statement from the Ministry of Research, Education and Digitalization. That number is higher than Denmark’s population of about six million because the register also keeps people who have died or moved abroad. People registered for name and address protection weren’t affected, the ministry said. Gadget Review called it reportedly the largest database leak in Danish history.
Christina Egelund, the minister responsible for digitalization, called it “a deeply serious incident.” She said the misuse went on for about 10 days and that security around the company’s access had not been good enough, The Copenhagen Post reported.
“I have requested that a thorough security review of the CPR system be carried out,” Ms. Egelund said. She has briefed the Danish Parliament’s business and digital affairs committee.
The CPR administration noticed irregular activity on the evening of Friday, Oct. 2, and found that the searches had been made in September, according to a notice on the register’s website. It then blocked the company’s access. The company hasn’t been identified.
It isn’t clear who ran the searches. Officials said it was too early to say, and no criminal group or state has been publicly blamed. Investigators haven’t confirmed whether ransomware was involved. They also haven’t said whether someone used one of the company’s own accounts or exploited some other weakness, The Copenhagen Post reported.
The intruders didn’t get into the register directly. Danish law lets private businesses with a justified need search the CPR, under Section 38 of the CPR Act, IT Security Guru reported. The 10-digit number is how Danish tax offices, banks and hospitals identify a person.
Nathan Davies-Webb of the security firm Acumen Cyber told that outlet that the perimeter controls, authentication and access rules had all worked. The weakness, he said, was that anyone working inside that legitimate access could read the data.
The Danish Data Protection Agency confirmed it got the breach report on Sunday. Police are investigating together with other agencies.
Officials told people not to give out passwords or other confidential information by phone or email, even when the person on the other end already knows their name, address and CPR number. The government’s Cyberhotline, at +45 33 37 00 37, will be open from 8 a.m. to midnight for the next few days.
Names, addresses and numbers may not be the whole of it. The register can also hold marital status, family relationships and membership in the Church of Denmark, and the ministry hasn’t said whether any of those fields were viewed, Cybernews reported.

