Denmark is investigating a major security breach involving its national population registry after unauthorised individuals gained access to personal information belonging to about 8.8 million registered people.

The compromised system, known as the Central Person Register (CPR), contains sensitive information used by Danish citizens and residents when accessing public services, healthcare and other essential services.

Danish authorities said the exposed information includes names, addresses and CPR numbers, which serve as personal identification numbers. The affected records include people currently living in Denmark, as well as individuals who have moved abroad and deceased persons.

The scale of the incident is significantly larger than Denmark’s population of roughly six million because the CPR contains information on approximately 11 million registered individuals.

Authorities said the attackers did not directly breach the central database. Instead, they allegedly exploited a Danish company that had legitimate access to search the CPR system, using that access to obtain information they were not authorised to retrieve.

The company’s access has since been stopped, while Denmark’s Data Protection Agency and police have been notified and are investigating the incident. Officials have not yet identified those responsible.

Research, Education and Digitalisation Minister Christina Egelund described the incident as “a deeply serious incident” and ordered a comprehensive security review of the CPR system.

Authorities have also urged affected individuals to remain alert to possible phishing attempts, warning that criminals may use stolen personal information to make fraudulent calls, emails or messages appear legitimate.

The breach was detected on October 2 after irregular activity was identified in the system during September.