Denmark's Central Person Register (CPR) — the backbone of Danish civic identity since 1968 — has suffered its most significant breach. Unauthorized actors hijacked a Danish company's lawful access to the CPR system and used it to extract names, addresses, and CPR numbers for approximately 8.8 million registered individuals. Denmark's population is roughly 5.9 million; the larger figure includes deceased persons and non-resident registrants. The attack vector is the story. This was not a zero-day exploit or a brute-force intrusion. It was credential abuse — someone took an authorized company's existing access rights and used them to query the system at scale. The CPR system, by design, grants thousands of private-sector entities lookup access for legitimate business purposes (banking, insurance, utilities, healthcare). Each of those access points is a potential door. The attacker walked through one of them. The CPR administration confirmed that individuals registered with name and address protection (navne- og adressebeskyttelse) were NOT included in the exfiltrated data. This is a meaningful carve-out — it means the system's privacy flag functioned as intended, even under hostile conditions. But for the remaining 8.8 million records, the exposure is comprehensive: full legal names, residential addresses, and the 10-digit CPR number that serves as Denmark's universal personal identifier across tax, health, banking, and government services. The company's access has been revoked. The Danish Data Protection Authority (Datatilsynet) has been notified, and police are investigating in coordination with other agencies and specialists. The Ministry of Higher Education and Science (Forsknings-, Uddannelses- og Digitaliseringsministeriet) has published a public statement. The forensic timeline — when access began, how many queries were made, and whether the data has been exfiltrated to third parties — remains under active investigation. The structural problem is not unique to Denmark. Every national identity system that grants API access to private companies faces the same topology: a single centralized database with many distributed access points, each of which inherits the security posture of its holder. The CPR system's value — universal coverage, single-source-of-truth for identity — is precisely what makes it a high-value target. The more entities that can query it, the larger the attack surface. Denmark now faces a remediation challenge with no clean solution. You cannot revoke 8.8 million CPR numbers without paralysing the entire civic infrastructure. The numbers are embedded in tax records, health systems, bank accounts, employment contracts, and government correspondence. Unlike a credit card number, a CPR number cannot be rotated. The exposed data is permanently compromised, and its utility for identity fraud, phishing, and social engineering will persist for decades. The incident is a live stress-test for the EU's post-GDPR enforcement apparatus. Denmark's Datatilsynet must now determine whether the company that held the access credentials maintained adequate security under Article 32 of the GDPR, and whether the CPR administration itself failed in its role as data controller by not monitoring for anomalous query patterns. The answers will set precedent for every member state running a centralized population register.