Skip to content
Bramble

Technology

Hackers access personal data of 8.8 million people in Danish national register

Denmark's government said unauthorised people accessed the names, addresses and CPR numbers of about 8.8 million people in the Central Person Register, via a Danish company that legitimately had access. An investigation is under way.

2 outlets · 0L · 1C · 1R First reported Account updated
Image: The Straits Times
Image: Anadolu Agency

1 / 2

The story, neutrally told

Mixed · 2Denmark's government said on 5 October 2026 that unauthorised individuals had illegally accessed the national Central Person Register (CPR), obtaining the names, addresses and CPR numbers of around 8.8 million registered people. Mixed · 2The register holds about 11 million people, including those who have died or emigrated, while Denmark's population is around six million, which is why the number of affected records exceeds the number of residents. Mixed · 2According to the ministry, the intruders got in through a Danish company that legally had the right to search the register.

Mixed · 2Digital affairs minister Christina Egelund called it "an extremely serious incident" (rendered by Anadolu as "deeply serious") and said authorities were working to map its full extent. Right · 1An investigation has been launched and the hackers have not yet been identified, according to the AFP report. Centre · 1Anadolu, citing the Danish broadcaster DR and the ministry, reported that the company's access to the register has been suspended and the Danish Data Protection Agency notified, and that people registered for name and address protection were not affected.

Centre · 1Egelund urged the public to stay vigilant and not to disclose passwords or other confidential information in response to calls, emails or other inquiries, even if the contact knows their name, address or CPR number.

Every sentence links to the reporting it rests on. The pill in front of each says where its sources sit: Left, Centre or Right when one side supplies at least half of them, Mixed when they are evenly split. The number is how many outlets it cites.

Left0 outlets

No left outlet in our sources has covered this story yet.

Centre1 outlet

Framing
Anadolu reports the incident as a security incident, citing DR and the ministry, with practical details on response and public advice.
Emphasis
Suspension of company access, data protection agency notified, exclusion of protected addresses, scam warnings.
Leaves out or plays down
Does not say the hackers are unidentified or that an investigation was launched.
Charged language
“deeply serious”
For example
“Authorities have suspended the company’s access to the register and notified the Danish Data Protection Agency.” — Anadolu Agency

Right1 outlet

Framing
Straits Times runs AFP wire copy that leads with the breach and the minister's quote, stressing the scale and that hackers are unidentified.
Emphasis
Scale of the breach, population versus register size, investigation under way.
Leaves out or plays down
Does not mention the protected-address exemption, the notification of the data protection agency or the minister's advice to the public.
Charged language
“extremely serious incident”
For example
“An investigation has been launched into the incident, with the hackers not yet identified” — The Straits Times