In short: On October 5, 2026, Danish authorities disclosed an "extremely serious" data breach: attackers accessed the names, addresses and CPR numbers (Denmark's national ID, similar to a Social Security number) of 8.8 million people — more than the country's entire population of just over 6 million, because the dataset also included deceased and emigrated citizens. The entry point wasn't a direct hack of the CPR population registry itself, but the legitimate access of a private Danish vendor, which attackers used to run bulk queries against the system throughout September. Leaks of this kind of personal data aren't a one-off — they're a systemic supply-chain risk that even government systems face.
What exactly happened
The Central Person Register (CPR) is Denmark's core population database, connected to banks, healthcare providers, employers and government services. Registry administrators spotted suspicious activity on the evening of October 2, 2026, and the investigation found unauthorized bulk queries had been running since at least September. Denmark's digitalization minister called the incident "extremely serious": names, addresses and CPR numbers for 8.8 million records were exposed — including data on people who have died or emigrated but remain in the system.
Why the vendor, not the registry, is to blame
The key detail is that attackers never breached CPR directly. They abused legitimate access granted to a private Danish company for its normal business operations, running a series of bulk queries through that channel. To the registry, those queries looked like ordinary partner traffic — which is exactly why the breach wasn't caught immediately, surfacing only weeks after the anomalous activity began. This is a textbook supply-chain risk: a core system's security is worthless if any one of the dozens of vendors with access to it is weaker.
The same pattern hit Japan the same day
The timing is telling: on October 5, 2026, Daiwa Securities — Japan's second-largest brokerage — disclosed a similar incident. Attackers breached vendor Scala Communications and accessed roughly 220,000 records, including names, email addresses and brokerage account numbers for up to 110,000 clients. Daiwa's own systems were never compromised — the break-in hit an external service provider. Two major breaches sharing the same attack vector on the same day isn't coincidence; it's a sign that attackers are systematically hunting for the weakest link not inside the target organization, but among its vendors.
What this means for ordinary users
If your data has ever landed in a government registry, a bank's CRM, a telecom's system or a clinic's records, you're relying not just on that organization's security but on every vendor it has granted "working" access to. A leaked name, address and national ID number is a ready-made toolkit for phishing, credit fraud and social engineering: an attacker calling a victim while already knowing their exact address and personal details makes a scam far more convincing.
How to reduce the risk on your end
- Treat calls and messages "from government agencies" or banks with extra suspicion — even if the caller cites your correct address or ID number: after breaches like this, that's no longer proof of authenticity.
- Turn on two-factor authentication everywhere you can, especially for banking and government portals — a name and address alone shouldn't be enough to access an account.
- Think about who you're sharing data with via third-party services — every vendor a company grants access to your data becomes a potential entry point, as this incident shows.
- Encrypt your traffic on public networks. A VPN won't prevent a breach on a government registry's side, but it closes a separate risk — interception of your data while you log into a bank or government portal over café or airport Wi-Fi. LiMP VPN is a no-logs service for Android, Windows and Chrome.
FAQ
A few quick answers to the questions this kind of vendor-access breach usually raises.
Sources
- Euronews — "Hackers accessed data of 8.8 million people in Denmark in an 'extremely serious' breach," October 5, 2026
- Computerra — "Denmark reveals a breach larger than the country's population," October 5, 2026
- The Japan Times — "Daiwa Securities says info on 110,000 clients may have been leaked," October 5, 2026
