Denmark's Central Person Register Data Exposed via Misused Legitimate Access
Roughly 8.8 million citizens had personal details leaked after attackers abused a private firm's lawful access rights to the national register.

Key points
- The Danish government confirmed the exposure of names, addresses and CPR numbers for 8.8 million people.
- Attackers exploited legitimate access granted to a private company rather than breaching external defences.
- The incident highlights how lawful access channels can be weaponised if internal controls fail.
The Danish government confirmed that unauthorised individuals accessed the Central Person Register, exposing sensitive data for approximately 8.8 million citizens. According to The Cyber Express, the breach involved the misuse of legal access rights held by a private firm. This incident underscores a growing trend where attackers exploit existing, authorised connections instead of forcing their way through hardened perimeters.
Root cause
The primary failure involved the misuse of lawful access granted to a private entity. A private company possessed legal credentials to query the national population database. Attackers misused this legal access to extract data. This mirrors other recent incidents where hijacked employee accounts or trusted third-party connections served as the initial entry point for data theft, according to The Cyber Express.
Attack path
The attackers leveraged the trust relationship between the state and the private entity. By abusing the pre-existing, legal access granted to the firm, they accessed the register. The Cyber Express notes that this method exploits "doors that were already open," such as a company's lawful access to a government register. The source states that the time between intrusion and discovery remains dangerously long.
Affected versions
This incident does not involve a specific software version or CVE. The exposure resulted from the compromise of access privileges rather than a code flaw. Consequently, no patch or update can resolve the underlying trust model failure. The risk applies to any system where third parties hold broad query rights to sensitive datasets without sufficient monitoring or least-privilege restrictions.
Mitigation
Organisations must review all third-party access to critical data repositories. Implement strict least-privilege principles to ensure external partners can only retrieve the minimum data necessary for their function. Monitor query patterns from trusted accounts for anomalies, such as bulk data extraction or unusual access times. Regularly audit and revoke unused credentials to reduce the attack surface available to adversaries who may compromise partner systems.
What to do and how to stay safe: Denmark
- Audit all third-party access rights to sensitive databases and revoke unnecessary permissions immediately.
- Implement behavioural analytics to detect abnormal data retrieval patterns from trusted accounts.
- Enforce strict data minimisation policies for all external partners accessing citizen or customer records.
- Review logging configurations to ensure all queries from privileged accounts are recorded and monitored.
General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
How many people were affected by the Danish data breach?
Approximately 8.8 million people had their names, addresses and CPR numbers exposed.
Did attackers hack the government database directly?
No, they misused the legal access granted to a private firm connected to the register.
Is there a software patch for this issue?
No, this was an access control failure, not a software bug, so no patch exists.



