A trusted access point became a massive security breach.
Copenhagen, Denmark
Hackers have accessed personal information belonging to approximately 8.8 million people in Denmark after exploiting the legitimate credentials of a private company connected to the country’s civil registration system. The compromised information includes names, addresses and CPR identification numbers, which are widely used across Danish banks, hospitals and tax services. The scale of the breach exceeds Denmark’s current population because the registry also contains records of deceased citizens and people who have emigrated. Authorities have described the incident as extremely serious.
The attack did not directly penetrate Danish government systems. Instead, the intruders used authorized access held by a private company that was legally permitted to consult the national CPR registry for commercial purposes. That distinction is crucial because it shows how a secure central system can still be exposed through a trusted external connection. The breach therefore highlights a growing cybersecurity problem: access granted to legitimate partners can become a vulnerability when their credentials or systems are compromised.

Authorities detected unusual activity on October 2, although investigators believe the attackers had been accessing the database since sometime in September. The compromised access was subsequently revoked, while Denmark’s data protection authority and police opened investigations into the incident. Officials have also introduced additional protections around the CPR system. As of Monday, authorities had not publicly identified the attackers.
The exposed CPR numbers are highly sensitive because they function as core personal identifiers across Danish society. Government officials have stressed, however, that possession of a CPR number alone is not sufficient to impersonate someone in most sensitive digital procedures. Denmark also uses MitID, a two-factor authentication system, to protect access to banking, government services and other critical platforms. People whose names and addresses were protected under special security provisions were reportedly not affected.
The immediate threat may now shift from the breach itself to fraud built around the stolen information. Criminals can combine legitimate names, addresses and identification numbers with phishing messages, fraudulent calls or fake authentication requests designed to extract passwords and one-time codes. Danish authorities have therefore urged citizens to treat unexpected communications with increased caution. The incident offers a broader lesson for digital governments worldwide: cybersecurity is only as strong as the weakest trusted gateway into the system.
Phoenix24: clarity in the grey zone. / Phoenix24: claridad en la zona gris.