Denmark's national registry, the central database linking every person who has ever held a Danish social security number, was compromised by hackers who accessed names, addresses, and national ID numbers for 8.8 million records. The figure exceeds the country's 6 million living residents because the registry retains data on deceased and emigrated individuals — meaning the database holds roughly 11 million entries total, and hackers reached about 80% of them. The attack vector was banal and devastating: legitimate login credentials belonging to a local company. This is not a zero-day exploit or a sophisticated state-level intrusion tool. It is the digital equivalent of walking through an unlocked door with a borrowed key. The compromised access pathway has since been shut down, but the data is already out. Digital Affairs Minister Christina Egelund called the incident "extremely serious," a phrase that understates the structural problem. The ministry was first alerted to an "anomaly" in the system "during September," meaning weeks or longer elapsed between initial compromise and detection. Danish news agency Ritzau reported the registry also contains information on church membership, legal incapacitation details, and restrictions on legal capacity — data categories that go well beyond basic identity information. The architecture of this breach is a textbook case of centralized fragility. Denmark consolidated identity data into a single registry accessible via third-party credentials, creating a system where one compromised vendor endpoint could expose the entire population. There is no indication of segmentation, tiered access, or anomaly detection that triggered faster response. The registry was built for administrative efficiency at the cost of resilience. The hackers have not been identified. The investigation is ongoing, with authorities still mapping the full extent of what was accessed and whether data was exfiltrated, sold, or staged for later use. For 8.8 million records including social security numbers, the downstream risk — identity fraud, phishing, social engineering — extends for years regardless of whether the attackers are caught. This is not a novel attack pattern. It mirrors breaches at the U.S. Office of Personnel Management (2015, 21.5M records), Optus in Australia (2022, 9.8M records), and Estonia's ID card vulnerability (2017, 750K records). The common thread: centralized identity databases with insufficient access controls and detection lag. Denmark's digital infrastructure is widely regarded as among Europe's most advanced, which makes the breach a stress test of the "digital-first governance" model itself. The core question is whether Denmark — and other countries running similar centralized registries — will treat this as a one-off incident requiring patching, or as evidence that the architecture itself needs redundancy, segmentation, and zero-trust access models. History suggests the former. The data suggests the latter.