Hackers broke into a Danish government database and walked off with personal records on 8 million people.
Denmark's government disclosed on October 5, 2026, that attackers broke into one of its databases and stole records on 8 million people. The haul includes names, home addresses, and the state-issued ID numbers Danes use for everything from banking to doctor's visits. The number is striking because Denmark has about 6 million residents - the dataset also sweeps in Danes living abroad and people who have since died. That breadth suggests the database functioned as a near-complete civil registry, not a narrow slice of current taxpayers or benefit recipients.
Unlike a credit card number, a national ID number is not something you can cancel and reissue. Once it's out, it's a permanent key for identity theft, fraud, and impersonation that follows people for the rest of their lives - and in this case, even after their deaths. For a country that uses this ID system as the backbone of nearly every government and financial interaction, a breach this size amounts to a structural weak point, not a one-off glitch.
Denmark now joins the lengthening list of governments learning that centralizing a nation's identity data in one place also means centralizing the risk.