
Denmark suffered a data breach affecting 8.8 million people in its central registry, raising questions about the security of digital identities.
AI-generated summary
Unknown perpetrators hijacked a private company's legitimate access to the Danish CPR register in September, extracting the data of 8.8 million people.
A digital showcase country, a leaky population register and a brand new identity wallet. Denmark launched its digital identity application in June, compliant with the future European standard. Four months later, it announced that the data of 8.8 million people had been sucked into its central registry. On the networks, the shortcut is quickly made. However, it deserves to be dismantled piece by piece, because it just touches a specific place.
Danish registry: 80% of the file siphoned off in ten days
Reminder of the facts, according to the press release from the Danish Ministry of Digital published on October 5. In September, unknown persons hijacked a private company's legitimate access to the CPR register, the file which lists everyone who has lived in Denmark. They extracted the names, addresses and national identification numbers of 8.8 million people, living, dead or gone abroad. Only people registered for identity protection escaped collection.
The file has approximately 11 million records. A simple business account was enough for intruders to view nearly 80% of them for ten days, according to the specialist site The Next Web.
Digital identity wallet: data in your pocket, not in a file
The Danish app is called AltID. Launched on June 4, 2026, it anticipates the obligation for European states to offer at least one digital identity wallet by the end of 2026, reports the Biometric Update website.
Its architecture is the opposite of a central register. The data stays on the phone and the user chooses what it shows. To prove its age, the application uses zero-knowledge proof, a technique popularized by blockchains. It confirms that you are over 18 years old without revealing your name, address or national number. Use remains optional.
To say that the European wallet reproduces the model of the hacked register is therefore inaccurate. On paper, it looks even better than the identity card you hand to the tobacconist.
Digital identity, DAC8: all recorded, all exposed?
However, here is where the doubt is founded. To create your AltID, you must first connect with MitID, the national digital identifier, itself linked to the CPR number. The wallet is decentralized, its source of truth is not. Each certificate it contains comes from a central base, the same one that has just fled.
Cryptocurrency holders are familiar with this pattern. You can keep your keys at home. If the platform where you purchased knows your name and address, a leak from them is enough to expose you.
And Brussels adds a layer with the DAC8 directive. Since January 1, 2026, crypto platforms have collected the identity of their customers and the details of their transactions to transmit them to the tax authorities. The administrations of the Twenty-Seven will exchange them no later than September 30, 2027. Each holder who has passed through a platform will therefore appear in a tax file, their address next to their transactions: a shopping list for those who know how to enter.
France knows what such a file is worth. A former employee of the Bobigny tax center is indicted, suspected of having consulted the addresses of investors in cryptocurrencies in the Mira tax software on behalf of third parties, according to Le Parisien. It had legitimate access, like the Danish company. The digital euro will ask the same question in a few years.
The ID wallet protects what you show, not what the state keeps on you. As long as central records remain accessible through third-party company accounts, the promise of “in-pocket” identity will have a blind spot. Member States of the Union have until the end of 2026 to propose theirs.

ZachXBT claims to have used $3.5 million of its own funds to infiltrate a Chinese money laundering network suspected of working for the North Korea-linked Lazarus Group. His investigation, revealed on October 5, made it possible to identify addresses associated with more than $12 million from the Bybit hack and to obtain the freezing of 442,000 USDT by Tether.

The Danish government announced on Monday the leak of the data of nearly 8.8 million people registered in the central population register, consulted illegally via access from a private company.

Near Intents has recovered all of the $3.8 million stolen in an attack on its cross-chain swap service, following a 48-hour ultimatum from its chief executive.

In the third quarter of 2026, cryptocurrency hacks resulted in the theft of $1.26 billion according to CertiK, despite a 40% increase in bitcoin over the same period. September was the worst month with $768.5 million lost, mainly due to code and infrastructure flaws. Net losses after recoveries amounted to 869.6 million for the quarter, while the sector's insurance capacity fell by 20% year-on-year. Major attacks have targeted Bitget, Liquid Network and Tectonic, exploiting vulnerabilities in third-party providers, cryptographic proofs and lending protocols. AI now accelerates the detection of flaws in smart contracts.

In its 2026 index published on September 23, Chainalysis ranks Brazil first in the world for crypto adoption, ahead of the United States. Latin American activity grew by 9.8%, driven by the massive use of stablecoins.

OpenAI fired three employees for sharing confidential information with a third-party organization. This case comes shortly after the cancellation of GPT-6.1 Astra.