October 6, 2026

Denmark witnessed one of the largest incidents of personal data breach in its history, after unauthorized parties exploited digital powers granted to a private company to access sensitive information belonging to about 8.8 million people, raising widespread fears of fraud and identity impersonation.
The Danish Ministry of Research, Education and Digitization announced on Monday that the hack targeted data from the Central Population Register, and included names, addresses and identity numbers. The Registry Administration, known by the abbreviation “CBR”, quickly cut off the relevant company’s access to the system immediately after discovering the incident.
The police and concerned authorities, in coordination with security experts, began extensive investigations to uncover the circumstances of the abuse of powers and determine the size of the affected data and the parties behind the operation, at a time when the authorities did not reveal the identity of those responsible, while reporting the incident to the Danish Data Protection Authority.
The hacking threads were revealed on the evening of Friday, October 2, after unusual activity was detected dating back to the month of September, and subsequent reviews over the weekend confirmed unauthorized access to the data of millions of individuals.
The announced number (8.8 million affected people) raised questions given that the population of Denmark is about 6 million people, but the authorities explained that the central registry contains about 11 million records, including data on people who have died or left the country. Initial reviews showed that the names and addresses of people subject to special protection arrangements were excluded, while investigations continue to determine the rest of the leaked data.
The Minister of Research, Education and Digitization, Christina Egelund, described the incident as “extremely serious,” noting that Parliament’s Business and Digitization Committee had informed it of it, and that practical steps had been taken to prevent its recurrence. The Minister also called for a comprehensive security review of the system and called on citizens to be extremely cautious.
The Danish authorities warned residents against disclosing passwords or sensitive data via phone calls or emails, noting that knowing the caller’s name, address, and ID number does not necessarily mean the legitimacy of his request or identity.
These developments come in light of growing security concerns in Europe regarding cyberattacks and leaks of major databases, especially with the increasing reliance on sensitive central systems, which makes any vulnerability in access permissions a widespread threat.