October 5, 2026

A huge hack reveals the identities of 8.8 million Danes and puts the authorities in a security dilemma

The Danish Ministry of Research, Education and Digitization announced on Monday that the data of about 8.8 million people had been exposed to a security breach, after unauthorized parties accessed the system by misusing powers granted to a private company.

The authorities explained, according to Agence France-Presse, that the powers granted to the company were exploited to illegally access data from the Central Population Register (CPR). Following the discovery of the incident, the Registry Administration quickly stopped the company’s access to the system, while the police and competent authorities, in cooperation with experts in digital security, began extensive investigations to determine the circumstances of the exploitation of the powers and the scope of the targeted data, at a time when the Danish Data Protection Authority was informed of the incident without revealing the identity of those responsible or their method of exploiting the company’s powers.

Details of the incident’s revelation go back to the evening of Friday, October 2, when the Registry Department monitored unusual activity dating back to last September. Audits conducted over the weekend showed unauthorized access to the data of millions of people.

While the number of 8.8 million affected people raised questions given that the population of Denmark currently amounts to a little more than 6 million people, the authorities explained that the central registry is not limited to current residents, but rather maintains information about people who have died or left the country, so that the system includes a total of about 11 million registered records. The initial review showed that the names and addresses of registered persons were excluded as part of special arrangements to protect information, while audits continue into the remaining details of the affected data.

For her part, the Minister of Research, Education and Digitization, Christina Egelund, described the incident as “extremely serious,” noting that Parliament’s Business and Digitization Committee had been informed of it, and that immediate steps had been taken to prevent its recurrence. The Minister also ordered a comprehensive security review of the system to address the gaps, calling on citizens to be careful and cautious during the coming period.