Denmark’s Central Person Register — the national database that assigns every resident a lifetime CPR number used for everything from banking to healthcare — has had the personal details of roughly 8.8 million people pulled out through unauthorised queries. Names, addresses, CPR numbers, and other identifying fields were exposed, covering living residents, people who have emigrated, and the deceased. The CPR administration flagged irregular activity on the evening of 2 October, but the queries had already been running undetected for about ten days by then. The company responsible for the account that was abused has been blocked from the system, and Danish police have opened an investigation.
What makes this incident especially instructive is the shape of the attack. The intruders did not break into CPR directly. They operated through a private Danish company that had legitimate, authorised access to search the register — and used that trusted channel to run queries far beyond anything the company was supposed to do. That is the hard problem with centralised identity systems: the central database is only as safe as the weakest third-party login tied into it, and in a modern government stack there are a lot of those logins. The pattern should feel familiar to anyone who read our write-up of the Canvas data breach, where millions of student records flowed out through an edtech vendor that was already inside the perimeter.
For individuals, the practical takeaway is uncomfortable. You do not get a say in whether your identity data sits inside a government register, and you do not get to vet every third party your country licenses to search it. What you can control is the surface area you expose everywhere else: the apps that know your location, the browser that leaks your identifiers across the web, the trackers that quietly build a profile from your daily browsing and sell it onward. The FTC’s recent ban on Kochava’s sale of precise location data made exactly this point from the commercial side: once your data is in the pipeline, you lose any realistic claim on where it ends up.
Minimising what leaves your device is the only move individuals can actually make. Incognito Browser, the best free privacy browser for Android, is built on exactly that premise: block the trackers that follow you between sites, wipe your session the instant you close the app, keep nothing stored on your device for a third party to lift later. It will not stop a foreign query on a government register in Copenhagen. But it will shrink the trail you leave on the far more exposed side of your life — the one you walk into every time you open a browser. You can install Incognito Browser free on the Google Play Store.


