Denmark says hackers stole data of 8.8 million people from national register
In short
The Danish government said hackers stole the data of 8.8 million people from the Central Population Register (CPR), according to Kommersant and Habr News. The stolen data includes names, addresses and personal identification numbers. Digitalisation Minister Kristina Egelund called it an “extremely serious incident”; it is not yet known who was behind the breach, which authorities say came through a private company that had access to the register and has since been cut off.
Why it matters
The CPR is a national register whose records cover about 11 million people, more than Denmark’s roughly 6 million residents, so the breach touches data far beyond the current population. Authorities say the entry point was a private company with access to the register, an outside contractor whose connection has now been severed, and the government has opened an internal investigation. The documents give no indication of the motive or of any confirmed culprit.
Key facts
- Danish authorities said hackers stole data on 8.8 million people from the Central Population Register (CPR) [ 1 , 2 , 3 ]
- The stolen data includes names, addresses and personal identification numbers [ 2 , 3 ]
- Digitalisation Minister Kristina Egelund called the incident “extremely serious” [ 2 , 3 ]
- It is not yet known who carried out the breach [ 2 , 3 ]
- Authorities said the hackers gained access through a private company that had access to the CPR, and that the company has been disconnected from the register [ 2 , 3 ]
- Suspicious activity was first noticed on 2 October, according to the authorities [ 2 ]
- Denmark’s population is about 6 million, but the CPR holds data on roughly 11 million people, including some deceased people and people who have left the country [ 2 ]
- The government has begun an internal investigation into the incident [ 3 ]
Confirmed by several sources
- Data on 8.8 million people was stolen from Denmark’s Central Population Register (CPR) [ 1 , 2 , 3 ]
- The compromised data includes names, addresses and personal identification numbers [ 2 , 3 ]
- Digitalisation Minister Kristina Egelund described the incident as “extremely serious” [ 2 , 3 ]
- Authorities say the access came through a private company with access to the CPR, which has since been disconnected [ 2 , 3 ]
- Authorities say it is not yet known who was behind the breach [ 2 , 3 ]
Still unclear
- Who carried out the breach and what their motive was Kommersant and Habr News both state that it is not yet known who stood behind the hack; no document names a suspect or group.
- Which private company had access to the CPR and was disconnected The documents say the hackers obtained the data through a private company with register access, but neither Kommersant nor Habr News names it.
- When the breach itself took place Only Kommersant gives a timing detail, saying suspicious activity was first noticed on 2 October; no document states when the data was taken or how long the access lasted.
- How the 8.8 million figure relates to the register’s roughly 11 million records Kommersant reports both figures and notes the register also holds data on deceased people and people who left the country, but no document explains exactly which records or time period the 8.8 million covers.
- The outcome and scope of the government’s internal investigation Habr News reports that a review has started, but no document describes what it will cover or when results are expected.
What local media are saying
Timeline, local time
- Suspicious activity is first noticed, according to the authorities [ 2 ]
- TASS reports that a leak of personal data on 8.8 million people has been identified in Denmark, citing the Central Register of Persons [ 1 ]
- Kommersant reports that hackers stole data on 8.8 million people from Denmark’s CPR, with the digitalisation minister’s reaction and the private-company access route [ 2 ]
- Habr News reports the leak and says the government has started an internal investigation [ 3 ]