Unauthorised parties used a private company’s lawful access to Denmark’s Central Person Register to retrieve names, addresses and national identifiers associated with about 8.8 million records.
What changed
The breach changes two enterprise assumptions at once: durable national identifiers must be treated as potentially public, and authorised third-party access must be monitored as a privileged data-extraction channel. The register holds about 11 million records, including living residents, emigrants and deceased people.
Public record through 2026-10-06. Source references count citations across published briefings, including repeated sources. Explore the record and its limits →
What We Publish / What We Sell
D
Free · Public
The Daily
Five evidence-backed selections for security leaders, every weekday.
Security.io editorial methodology: Exposure measures affected population and data reach; Urgency measures immediate control decisions; Business consequence measures fraud, assurance, regulatory and operating-model impact. Exposure: 98. Urgency: 88. Business consequence: 92. Focus the chart and use the up and down arrow keys for detail. Source: Security.io editorial scoring from 0–100, based on the selected sources and weighted for blast radius, identity reuse, delegated access and response uncertainty.