Hackers stole records on 8 million people from Denmark’s national citizen database

Denmark handed hackers a near-complete picture of its entire population. That’s the practical result of a breach that compromised the country’s Central Person Register, a government database holding records on roughly 11 million people, including Danish citizens living abroad and the deceased. According to TechCrunch, the stolen data affects around 8 million individuals and includes names, home addresses, and Danish social security numbers, which are used for filing taxes and accessing public services.

Danish minister Christina Egelund called it a “serious incident.” That’s an understatement. Social security numbers tied to real names and addresses are exactly the kind of data that enables identity fraud, targeted phishing, and long-term impersonation. This isn’t just an embarrassing leak. It’s a structural problem for every Danish citizen whose information now sits in someone else’s hands, possibly forever.

What makes this breach especially troubling is how the attackers got in. The Danish government confirmed that the unauthorized access came through a Danish company that had legitimate, legal access to the CPR system. Many private companies in Denmark can query the register to verify personal information against government records. Someone abused that access. The government has not named the company or identified who carried out the attack, which happened in September and was only discovered on October 2.

This is the part that deserves more scrutiny. When you build a system where dozens or hundreds of third parties can pull data from a national identity database, you multiply your attack surface with every access point you grant. The breach wasn’t caused by a hacker cracking government servers directly. It came through the supply chain of trusted access. That distinction matters because it means the fix isn’t just better government security. It’s about rethinking who gets access, how much they can pull, and what monitoring exists to catch abuse in real time.

Denmark is not alone in this. A 2016 cyberattack exposed millions of Turkish citizens’ identity records. India’s Aadhaar database, one of the largest biometric identity systems in the world, has suffered multiple data exposures over the years. The pattern is consistent: centralized national databases are high-value targets, and when they fall, the damage is wide and nearly irreversible.

This breach is believed to be the largest in Danish history. And it raises a question governments keep avoiding: is a single, centralized citizen database worth the risk it creates? The convenience is real. So is the damage when it fails.