Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
Denmark Says Hackers Accessed CPR Data on 8.8 Million People Through a Private Company's Backdoor

Denmark's government confirmed Monday that unauthorized individuals got into the country's Central Person Register, known as CPR, and pulled personal data on roughly 8.8 million people.
The data included names, addresses and CPR numbers, Denmark's version of a Social Security number, according to a statement from the Ministry of Research, Education and Digitalisation. Denmark's population is about 6 million. The CPR database holds records on 11 million, because it also tracks people who've died or moved abroad, according to the ministry and reporting from the Copenhagen Post.
"This is a deeply serious incident," Digitalization Minister Christina Egelund said, according to the Copenhagen Post. She briefed the Folketing's Business and Digitalisation Committee on it and said authorities are "in the process of mapping out the full extent of the incident."
How It Happened
This wasn't a brute-force hack of government servers. According to the ministry, unauthorized parties abused a private Danish company's legitimate, lawful access to search the CPR system. In plain terms: a vendor with a legal key to the database got compromised, and whoever got in used that key.
The CPR administration first noticed something was off on Friday evening, October 2, according to the Copenhagen Post. Over the weekend, officials determined the unauthorized searches had actually happened back in September, and pinned down the approximate scale of who was affected.
People enrolled in Denmark's name and address protection program were not exposed, the ministry said. Beyond names, addresses and CPR numbers, the register can also hold marital status, birth registration details, family relationships, church affiliation and legal incapacitation status. The ministry has not said exactly which of those additional categories were accessed.
Key Discrepancy
There's a real discrepancy in the record on one basic point: has the company's access been cut off?
AFP's original wire report, carried by Euronews, the Manila Times, Punch Nigeria and Leadership Nigeria, states plainly that "the access has not been revoked." But Bloomberg's reporting, carried by Business Standard, and the Copenhagen Post's own reporting both say the company "has since been blocked" from the system, with the CPR administration describing it as already blocked.
If the company's access was still live when the ministry made its public statement, that represents a significant gap in an emergency response to a breach involving 8.8 million people. If it had already been cut off by Monday, as the Copenhagen Post and Bloomberg report, that's a more defensible timeline. The ministry's own statement doesn't fully resolve which version is accurate, and no source has identified the company by name, which makes it harder for the public to judge whether the fix actually happened.
Who's Investigating, and What's Still Unknown
Denmark's police are investigating, and the case has been formally reported to Datatilsynet, the Danish Data Protection Agency. Datatilsynet confirmed it received notification from the CPR register on Sunday, October 4, and said Monday it's too early to assess the specifics or comment further.
Authorities say they currently have no information on who carried out the breach. Egelund has ordered a full security review of the CPR system and says the government has already launched initiatives aimed at preventing similar incidents, though she hasn't detailed what those are yet.
The Bigger Question This Raises
Denmark runs one of the most digitized public sectors in the world. The CPR number is the master key residents use with government agencies, banks and hospitals alike. That convenience is the whole point of the system, and it's also exactly why a breach like this one matters more than a typical corporate data leak. When a single registry holds cradle-to-grave records on every resident, and outside vendors are routinely granted legal access to query it, the attack surface isn't the government's firewall. It's every third party the government has decided to trust.
Egelund is urging Danes to stay alert for suspicious calls and emails in the coming weeks, a standard warning given how useful a real name, address and national ID number is for phishing and identity fraud. Whether the vendor that got compromised faces any penalty, and whether Denmark tightens who gets legitimate access to CPR data going forward, are the two open questions the police investigation and Datatilsynet's review are expected to answer.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.