Denmark’s Central Population Register (CPR) is warning that a data breach has exposed personal information for about 8.8 million people. The CPR is Denmark’s national resident register, and it assigns each person a 10-digit CPR number used in many public services and private transactions.

Multiple outlets report that the CPR administration became aware of the breach on the evening of Friday, 2 October 2026. The exposed data includes names, addresses, and ID-related information tied to the CPR number. The breach affects people living in Denmark, deceased people, and citizens who have moved abroad, according to coverage.

Reporting also says that the incident involves unauthorized use through a company’s legitimate access pathway. The Danish digitalisation ministry announced the breach on Monday, and the CPR administration blocks the company’s access. Police are investigating the matter; one outlet also reports that there were extensive lookups—about 14 million in roughly ten days—before the issue was identified.