Nobody broke into Denmark's central population register. According to the Danish authorities, as relayed by TNW, The Register, BleepingComputer and SecurityWeek, unknown users abused the legitimate access of a small private company and pulled records for about 8.8 million people. The first sign was not an alert from a security tool. It was an unusually large invoice, spotted on the evening of Friday 2 October when the register's administration billed the company for its lookups.
That sequence is the useful part of the story. A pay-per-lookup register turned out to have an accidental anomaly detector in its billing run, and the identifier it exposed, the CPR number, does a job in Danish life that makes a name-and-address leak much more than a nuisance. The figures below come from a 6 October briefing by officials and from press coverage of it; the company and the attackers have not been named.
What was taken, and how little was hacked
Private companies with a legitimate interest can obtain CPR data under section 38 of the Danish Civil Registration System Act, subject to the ministry's access terms. Per The Register, access covers a defined group of people the company identified individually in advance. The company in question had that kind of access. The ministry's account, as reported, is that unknown users misused it.
The numbers: well over 14 million lookup attempts, of which about 8.8 million returned a record, according to TNW. The exact attempt figure was not given. The data exposed was names, addresses and CPR numbers; people with name-and-address protection were not affected. BleepingComputer reports that the Danish Data Protection Agency described the method as some form of brute-forcing to enumerate valid CPR numbers and then extracting the associated data. Christina Egelund, the minister responsible, said systems that rely on MitID, Denmark's national digital login, were not touched, per TNW.
The scale needs a denominator. The register holds roughly 11 million entries, including people who have died or moved abroad, according to The Register, which is why 8.8 million is not a statement about living residents of a country of about 6 million. By our arithmetic, 8.8 million out of 11 million is about 80 percent of the register, and 8.8 million out of at least 14 million attempts is a hit rate of at most about 63 percent. Because the attempt count is 'well over' 14 million, the true hit rate is somewhat lower.
Found by an invoice
Companies pay for each lookup. According to TNW, Mikkel Leihardt, a department head at the ministry, said the abuse surfaced during invoicing on Friday evening, when a very large amount was billed. The ministry then established the scale over the weekend, police from the National Unit for Special Crime visited the company on Saturday evening to secure evidence, and the breach was announced on Monday 5 October.
There is a timing question. TNW reports that the lookups ran for about ten days in September, and The Register and BleepingComputer say the activity occurred in September and was discovered on 2 October. SecurityWeek's wording is that the register was notified of abnormal behaviour 'during September'. The sources can be read as consistent (activity in September, discovery on 2 October), but SecurityWeek's phrasing leaves open whether anything was flagged earlier, and no source says. We do not try to settle it.
What the detection path implies is our inference, not the ministry's. If the abuse came to light in an invoicing run, then the lag between the start of the lookups and their discovery was set by the billing cycle, not by any monitoring of the access itself. The 14 million attempts also contain a signal that billing could not see: roughly 5 million or more of them returned nothing. A business looking up customers it already knows rarely misses. A high miss rate is what enumeration looks like.
The hit rate is itself informative. A CPR number is a six-digit date of birth followed by four further digits. Blind guessing across a century of birth dates would hit a registered number only a few percent of the time, by our back-of-envelope estimate of 11 million entries spread over roughly 365 million candidate strings. A rate approaching 63 percent suggests the guesses were not blind. We cannot say what narrowed them. That is exactly the kind of detail the investigation has not released.
Then there is the ministry's own description of the access terms: a group of people identified in advance. Either that list was enormous, or the system did not enforce it at the point of lookup. The Register reports that it has asked the ministry why such broad access was granted. Nothing in the coverage answers that yet.
A number that is both identifier and password
The lasting damage is not the address. People's addresses are widely known. The damage is that the CPR number sits at the centre of how Danes deal with public and private services, and some services treat knowing it as evidence of who you are. Laila Reenberg, head of the Styrelsen for Samfundssikkerhed, said companies and authorities should stop accepting a CPR number alone as proof of identity, and she described it as unsuitable for authorising purchases or releasing sensitive personal information (TNW). Jan Kaastrup, a private digital investigator, told TV 2 that treating the number as a secret is a broken approach.
That is an authentication failure that predates the breach. An identifier is meant to be shared; a credential is meant to be secret. The CPR number is handed to employers, banks, pharmacies and doctors by design. Once 8.8 million of them are in unknown hands with matching names and addresses, any service still using the number plus a name as verification has lost its protection for most of the register. The authorities' own advice, reported by BleepingComputer, is to be wary of unsolicited contact even from callers who know your name, address and CPR number.
The fix cannot be only a new register policy. Egelund said it is too early to say whether affected people will get new numbers, and has ordered a security review with no deadline (TNW). Reissuing numbers for millions of people would be a large administrative operation, and it would not help if the services that accept the number as proof stay the same.
The other side of the argument
There is a fair defence of the register. A legitimate access right was used, the authorities acted within days of discovering it, the company's access was blocked, the Data Protection Agency and police were notified, and the minister told Parliament's committee promptly. On this view, a system that lets pre-approved businesses look people up will always have an abuse risk, and the more useful question is why this company's controls failed, which is for the investigation to answer. The ministry has not said whether the company broke its terms, and we do not assume it did.
The counter to that defence is about where the controls live. A register that depends on its customers' security to protect 8.8 million records has delegated most of the protection. Per-customer lookup ceilings, alerts on miss rates, enforcement of the pre-declared list at lookup time, and billing alerts that run daily instead of at invoicing are the obvious candidates. None has been announced; these are our suggestions, drawn from the failure mode described.
What the numbers don't tell us
- The company is unnamed and how its access was abused is not known: stolen credentials, an insider or a compromised system are all possible, and no source says.
- The lookup count is 'well over 14 million', not exact, so the hit rate is a ceiling.
- When the abuse began is unconfirmed beyond 'September', and it is not clear whether anything was flagged before 2 October.
- Police had identified and charged no one as of the 6 October briefing, according to TNW's account of Henriette Erbs of the National Unit for Special Crime.
- Whether the data has been misused or published is unknown, and so is the split between living and deceased people among the 8.8 million.

