On October 5, the Danish Ministry of Research, Education and Digitalization announced a large-scale security incident involving the Central Person Register (CPR). The leaked information includes names, addresses, and CPR numbers. CPR numbers are personal identification numbers used for identity verification in administration, banking, healthcare, and more, equivalent to Japan's My Number system.

The incident did not involve the government's CPR system itself, but rather the access of a Danish company with legitimate authorization to search the CPR was exploited by a third party, leading to the acquisition of a large volume of information. According to authorities, a significant number of automated searches were conducted with the aim of identifying valid CPR numbers.

The CPR currently holds data for approximately 11 million people, including those who have moved abroad and deceased individuals. The approximately 8.8 million people affected by the unauthorized access account for 80% of all registered individuals. However, the names and addresses of individuals who use a protection scheme to keep their names and addresses private were not affected.

The government has issued a warning, advising people not to trust anyone just because they know their name, address, or CPR number.