Denmark's population register exposed 8.8 million people. Denmark has 6 million residents.
Someone "abused" a private Danish company's legitimate access to the Central Population Register (CPR) and reached the details of about 8.8 million people, The Register reported on Tuesday.
The data includes names, addresses, identification numbers and other personal information.
The figure is larger than the population because the register holds roughly 11 million records, including people who have died or moved abroad.
The CPR administration said it became aware on 2 October of irregular activity during September. It blocked the company's access and notified Datatilsynet, the Danish Data Protection Agency. Police are investigating. The ministry said names and addresses of people registered with name and address protection were not exposed.
Digitalisation minister Christina Egelund said it was too soon to say whether Denmark would issue new personal ID numbers.
A company can hold legitimate access without every lookup having a business purpose. The report does not say what the company's access allowed, or how many lookups were made in September.
For each outside firm that reads the personal records you hold, can you match what it pulled to what it was allowed?
Image: AI-generated.
Sources
Every story here is open to read. The ERP LEADERS brief goes one step further.
The week in enterprise software, in one email: the stories that mattered, the failures with their figures, one case taken apart. Read a sample or sign up for the brief.
Welcome back. · Issue 01



