Nobody Broke Into Denmark's Population Register. Someone Used a Company's Key, and 8.8 Million People Came Out.
Denmark's Ministry of Digitalization said on Monday, October 5, that the names, addresses and CPR numbers of about 8.8 million people were taken from the Central Person Register, the national population register that every Danish public service runs on. Nobody broke the register's defenses. According to the government's statement, unauthorized parties used a private Danish company's legitimate access to search the CPR system during September. The irregular activity was spotted on the evening of October 2. By the weekend, investigators had confirmed the searches. The company's access has been revoked and Datatilsynet, the Danish data protection authority, has been notified.
Digitalization Minister Christina Egelund called it "deeply serious" and ordered a full security review of the CPR. The company has not been named. Nobody has been publicly attributed. Authorities have not said how the unauthorized parties got hold of the company's access, and they have not said whether it was the company, someone inside it, or a thief holding its credentials. We won't guess.
The number is bigger than the country
Denmark has about 6 million residents. The register holds about 11 million records, because it keeps people who have died and people who have emigrated. So 8.8 million is roughly 1.5 times the living population of Denmark, and about 80 percent of everyone the register has ever held. If you were born in Denmark, lived there, or worked there long enough to be assigned a CPR number, you should assume you are in it. That includes people who left decades ago and the families of people who have died.
People with name and address protection were not exposed, according to the government. That is the one control in this story that held exactly as designed.
The seam: register-wide reach handed to a private company
Here is what is worth understanding. Denmark lets approved private companies, such as banks, insurers and debt collectors, look people up in the CPR. That is a normal and useful thing. The government's own description is that the unauthorized access "took place within the categories of information available to private companies through the CPR system." In other words, the searches stayed inside what the key was allowed to open.
So the access control did its job. It checked the credential, the credential was valid, and it answered. What nobody seems to have owned is the next question: how much is one company's credential allowed to read in a month? A bank checking a customer's address does not need 80 percent of a nation's register. The scope of the key was "anyone in the register." The scope of the business need was "our customers." The gap between those two is a trust boundary that sat between the government, which issues the access, and the company, which holds it. Each side could reasonably believe the other was watching the volume. We call this the shared-responsibility seam, and it is where most of the failures we write about actually happen: every control works, and the handoff between them belongs to nobody.
The detection happened, which is to the CPR administration's credit. But the searches ran through September, and the flag went up on October 2. A rate ceiling on that one credential would have tripped in days, not weeks.
The same week, the same shape, at DTU
On October 2, the Technical University of Denmark disclosed that attackers had reached DTUBasen, its identity and access management system, which holds user records back to 2003. Per DTU's statement to DR and reporting by The Copenhagen Post, the attackers got in by compromising several DTU user profiles. About 200,000 people may be affected, roughly 40,000 active users and 160,000 former ones: staff, students, guests and partners. The data includes CPR numbers and full names, plus home address and phone number for active users.
Again, nobody broke a wall. Valid accounts opened a database that held far more than any one of those accounts needed. Nobody has linked the DTU breach to the CPR breach, and we are not linking them either. They are two incidents with the same shape, in the same country, in the same week, and both ended with CPR numbers in somebody else's hands.
What about the Russian hacktivists?
Expect to see OpDenmark brought up this week. It's worth getting the dates right. In late January 2026, a pro-Russian alliance calling itself the Russian Legion (Cardinal, The White Pulse, Russian Partizan and Inteid) threatened Danish companies and public bodies over a 1.5 billion DKK aid package to Ukraine. Truesec covered it on January 30 and February 6. Truesec assessed the group as "likely state-aligned but not state-funded," found that the campaign "has only consisted of" DDoS attacks, and warned that such groups use language "to create fear and doubt far beyond their actual capabilities."
No source we have found connects the Russian Legion, or any other group, to the CPR searches or to DTU. A lookup run through a legitimate commercial account is a very different operation from a DDoS run through a botnet. If someone tells you this was OpDenmark, ask them for the evidence.
What we hold
We checked our own corpus before writing this. We have nothing on the CPR breach, on DTU or DTUBasen, on OpDenmark, or on the Russian Legion. Searches of our indicator index for each of those return zero, and our blog has never covered any of them. The only related record is our adversary profile for NoName057(16), a different pro-Russian DDoS crew that targets NATO countries.
No government or vendor has published network indicators for either breach. The CPR intrusion used a company's valid access, which leaves nothing for a blocklist. The only technical artifact in Truesec's OpDenmark reports is the group's Telegram channel, which is a place they talk, not infrastructure you can block. So we hold no indicators for this story and have added none to our feed. We have no lead to claim here. We are reporting this, not detecting it.
The same shape, closer to home
This isn't a Danish problem. Anywhere a government register is opened up to private buyers with broad search rights, the same seam exists. In the US, the Driver's Privacy Protection Act lets state DMVs sell driver records for "permissible uses," and the states make real money from it: Florida took in about $77 million in 2017, according to local investigative reporting. Data brokers then resell what they buy. Every one of those buyers holds a key that can read far more than its stated purpose needs. The question to ask is the same one Denmark is now asking: who is counting how much each key reads?
We apply this to ourselves too. Every API key we issue has a per-minute ceiling, and our registration gates refuse free keys to rented cloud machines. That is not because we distrust the people we register. It is because a valid key is the easiest way in, and the volume it reads is the one thing an attacker holding it cannot hide.
What you can actually do
If you are a Danish citizen, or ever were: assume criminals now have your name, address and CPR number. The authorities have specifically warned people not to give passwords or sensitive information to callers, even callers who already know your personal details. Knowing your CPR number proves nothing about who someone is anymore. Be wary of any call, text or email that uses those details to build trust, and never read out a code from your phone to anyone who calls you. If an older relative, or the family of someone who has died, may be in the register, tell them too.
If you run a municipality, a school, a clinic or a small agency: you probably hold or reach a citizen registry through a vendor, and a vendor probably reaches yours. None of this costs money. List every outside party with lookup access into your citizen or customer records. For each one, write down roughly how many lookups a month its job needs, and ask whoever runs the system to alert at a few times that number. Review the list every quarter and cut access nobody is using. Treat a vendor's credential as part of your own attack surface, because in this breach it was the whole attack surface.
If you issue access to a register: scope the key to the purpose, not to the database. Log the reason for each query. Alert on volume per credential, not just on failed logins. A login that succeeds is the case your detection has to cover.
Sources
Government statement and reporting dated October 5, 2026: CyberInsider, Insurance Journal, GBHackers, and Cybernews. DTU, disclosed October 2: DR and The Copenhagen Post. OpDenmark: Truesec, January 30 and February 6, 2026. DMV data sales: Action News Jax and The Drive.
The facts above are as of October 5, from the sources listed. The investigation is in its early days, the company is unnamed, and how the access was obtained has not been disclosed. We hold this at about 95 percent confidence. The other 5 percent is everything the Danish authorities have not said yet.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=nobody-broke-into-denmark-s-population-register-someone-used-a-company-s-key-and-8-8-million-peopl