Denmark's central population registry, known as CPR, was breached in September after unknown individuals hijacked the legitimate access credentials of a private company, the Danish Ministry of Digitalisation disclosed in a press release on 5 October. The intrusion exposed the names, addresses and national identification numbers of 8.8 million people, living, deceased or moved abroad. Those registered under identity protection were not affected.
The CPR registry holds roughly 11 million records in total. According to the ministry, intruders accessed nearly 80% of the file. The Next Web reported the unauthorised access lasted ten days before it was detected and shut down.
The timing has drawn attention because Denmark launched its digital identity app, AltID, on 4 June 2026, only months before the breach came to light. AltID is built on a decentralised architecture, but logging in requires MitID, the national digital identifier that is itself linked to the CPR number. The wallet's design does not remove the dependency on the central registry that was compromised; it sits on top of it.
A deadline Brussels cannot ignore
The episode lands as the European Union requires every member state to offer a digital identity wallet by the end of 2026. Denmark's experience is a live example of the trade-off regulators have been asked to manage: a wallet can be architected to minimise what it shares, but if the underlying national registry it authenticates against is breached, the wallet inherits that exposure regardless of its own design.
The breach also arrives alongside a separate EU data-handling obligation already in force for crypto. The DAC8 directive, effective since 1 January 2026, requires crypto platforms to collect client identity and transaction details for tax authorities. Member states are due to exchange this data with one another by 30 September 2027 at the latest, meaning identity and transaction records tied to crypto holders will flow between national tax administrations well before that deadline.
A separate case in France
The question of who can be trusted with such data has a parallel case in France. A former employee of the Bobigny tax centre is under formal investigation after, according to a report by Le Parisien, she allegedly consulted crypto investors' addresses in the Mira tax software on behalf of third parties. The case predates the CPR breach and involves a different system, but it illustrates the same underlying risk that EU-wide frameworks like DAC8 are meant to manage: identity and address data held by tax authorities can be accessed improperly, whether by outside intruders or by insiders with legitimate credentials.
Neither case has been shown to involve a flaw in AltID's own cryptographic design or in DAC8's reporting architecture. What both expose is the same structural point: centralised registries and software used to authenticate identity or administer tax data remain a single point of failure, even when the systems built on top of them are decentralised by design.



