Denmark has confirmed the largest data breach in its history. Hackers stole the contents of the country's Central Person Register — the central database of citizens' data — compromising records belonging to some 8 million citizens and residents, including people living abroad and the deceased.
The breach, disclosed on October 5, exposed names, addresses, Danish social security numbers, and other personal information. Danish minister Christina Egelund called it a "serious incident." The unauthorized access happened in September but was not discovered until October 2.
What makes the incident especially instructive for IT professionals is the attack vector. The government said the hackers obtained access by abusing a Danish company's lawful access to search the CPR system — legitimate third-party access, weaponized. Some Danish companies hold CPR search rights for identity verification purposes, and the attackers rode that trusted channel straight into the national database.
The scale is sobering. Denmark's population is roughly 6 million, but the CPR holds records for about 11 million people, with some data going back decades. That means the stolen 8 million records represent the overwhelming majority of the register — a near-total compromise of a nation's identity backbone.
The breach follows a grim lineage of national identity database attacks, including a 2016 breach affecting millions of Turkish citizens and repeated exposures from India's Aadhaar system. Centralized identity registers are high-value targets by design: one breach yields the keys to tax, healthcare, and government services for an entire population, and the data — names, birth dates, national ID numbers — cannot be reissued the way a credit card can.
For enterprise security teams, the Danish case is a textbook third-party risk failure. The perimeter held; the trusted partner channel did not. Organizations should be auditing not just their own access controls, but the access they've granted to vendors, contractors, and partners — and asking what happens when that trust is abused. The Danish government has not attributed the attack, and the investigation continues.