
The names, addresses and identification numbers of nearly 8.8 million people were accessed through legal access by a private company.
The Danish government announced on Monday the leak of the data of nearly 8.8 million people registered in the central population register, consulted illegally via access from a private company.
AI-generated summary
The CPR register has assigned a ten-digit number to every Danish resident since 1968, serving as a universal access key.
An entire country in a single file. The Danish government announced this Monday, October 5, 2026 that unknown persons have obtained the names, addresses and identification numbers of nearly 8.8 million people registered in the central population register. No system was forced, since the intruders passed through the legal access of a private company. French readers have known the music since the hacking of the FICOBA file, which exposed 1.2 million bank accounts.
CPR register: 8.8 million cards vacuumed without break-in
Friday, October 2 evening, the CPR administration noticed irregular behavior in its system. It dates back to September. The weekend was enough to measure the damage.
According to the ministry's press release, third parties have hijacked a Danish company's access to query the register. They thus consulted the names, addresses and CPR numbers of around 8.8 million registrants. The figure exceeds the population of the kingdom, which has around 6 million inhabitants, because the register also keeps people who have died and those who have gone to live abroad.
The CPR is the ten-digit number assigned to each resident since 1968. It serves as an entry key to the bank, the doctor or taxes. The system now has around 11 million records, which means that four out of five have been consulted. Only people placed under name and address protection are exempt.
Misused legal access, the weak point of the national identifier in the face of data leaks
No one broke a lock. Danish law allows private companies with a legitimate interest to obtain information about people they have already identified, and the intruders stayed within that scope. The administration cut off access to the company concerned, seized Datatilsynet, the Danish equivalent of the CNIL, and the police are investigating.
Christina Egelund, Minister of Research, Education and Digital, speaks of a “profoundly serious incident”. She informed the relevant parliamentary committee and ordered a thorough security review of the system. The authors remain unknown. The ministry also warns that the figures may still change as the investigation progresses.
Let's be fair, the press release does not mention any password or banking information, even if its list ends with an "etc." ". The danger is elsewhere. Copenhagen reminds you to never communicate a code by telephone or e-mail, even when the interlocutor knows your name, address and CPR number. A helpline remains open from 8 a.m. to midnight for the next few days.
Centralized digital identity: why crypto holders should watch Copenhagen
You change a password in two minutes. A CPR number follows a Dane all his life. Once removed from the register, it cannot be revoked, and the scammer who calls while reciting it immediately gains the trust of his victim.
For those who hold bitcoin, the subject is concrete. A private key kept in self-custody, that is to say by its owner and without an intermediary, does not appear in any State file. Your postal address, yes. However, Europe is moving in the same direction as Denmark, since the eIDAS 2 regulation requires each member state to offer a digital identity wallet by the end of 2026.
AI outlook — possibilities, not facts
In-depth system security review by the Danish government
Very likely · Within weeks

Near Intents has recovered all of the $3.8 million stolen in an attack on its cross-chain swap service, following a 48-hour ultimatum from its chief executive.

In the third quarter of 2026, cryptocurrency hacks resulted in the theft of $1.26 billion according to CertiK, despite a 40% increase in bitcoin over the same period. September was the worst month with $768.5 million lost, mainly due to code and infrastructure flaws. Net losses after recoveries amounted to 869.6 million for the quarter, while the sector's insurance capacity fell by 20% year-on-year. Major attacks have targeted Bitget, Liquid Network and Tectonic, exploiting vulnerabilities in third-party providers, cryptographic proofs and lending protocols. AI now accelerates the detection of flaws in smart contracts.

In its 2026 index published on September 23, Chainalysis ranks Brazil first in the world for crypto adoption, ahead of the United States. Latin American activity grew by 9.8%, driven by the massive use of stablecoins.

OpenAI fired three employees for sharing confidential information with a third-party organization. This case comes shortly after the cancellation of GPT-6.1 Astra.

The Ethereum Foundation launched zkAPI, a protocol for paying for AI services via Ethereum without tying requests to an identity or account, ensuring anonymity of transactions through zero-knowledge proofs.

The Base network (Layer 2 of Coinbase) has activated the Cobalt update. It introduces 'Validity Transactions' for private conditional orders and extends the B20 standard, enabling complex compliance management and on-chain administrative entries.