Hackers are suspected of having cracked the Danish government’s national database containing the personal information of nearly nine million people, potentially exposing them to fraud or identity theft.
Copenhagen’s Ministry of Research, Education and Digitalisation said on Monday that the Central Register of Persons (CPR), the national civil registration database containing personal information for millions of citizens, has been compromised.
In Denmark, all legal residents have a unique 10-digit civil registration number, used to access public services, healthcare, banking, and taxes, and to store information on each citizen, including name, date of birth, address, marital status, citizenship, religious affiliation, and parentage.
The government said on Monday that unidentified people used a Danish business’s access to the system to wrongfully obtain the CPR numbers, names, and addresses of around 8.8 million people, the public Danish Broadcasting Corporation (DR) reported.
In a briefing on Monday, government minister Christina Egelund said that it was too early to tell whether it was a cyber attack or whether foreign state actors were involved in the leak.
“We are not ruling out any clues in the ongoing investigation. Nor that it may have an international character,” she said.
Egelund added that the government will review the entire CPR system and implement “adjustments and transformations” to re-establish security.
Professor of cybersecurity at Aarhus University, Jens Myrup Pedersen, said that while a CPR number falling into the wrong hands poses relatively little danger, it can become problematic if malign actors use it alongside other information.
Professor Pedersen said that if hackers obtained a person’s CPR number and combined it with a picture from their social media, they could use it to forge a driver’s licence and risk identity theft.
The most likely use of a CPR number and the other information in the leak would be to target victims with phishing attacks. Pedersen noted that because the register lists people’s ages, hackers could use that information to target older people, who are most vulnerable to phishing attempts and other fraud.
“Now the scammers know you better than they did before. And that increases their credibility,” he said.
The major leak comes amid a broader push throughout Europe to digitise information on its citizens. Indeed, by the end of the year, Brussels has mandated that member states provide their citizens with a European Digital Identity Wallet (EUDI Wallet).
While systems may vary by country, the digital ID will store a wide range of information about holders, such as travel, healthcare, education, banking, and social security documents, among others.

