Denmark is confronting a data breach that reaches more people than actually live in the country. What the government and the company at the center of it say from here could follow them for years.
On October 5, the Danish government revealed that intruders had taken the names, addresses and national ID numbers of about 8.8 million people from the country's central population register. Those ID numbers are the Danish equivalent of Social Security numbers, and the register also includes people who have died or moved abroad. The intruders got in by misusing a private Danish company's legitimate access to the system during September, and officials say the breach was discovered on October 2.
Digitalization Minister Christina Egelund called it “a deeply serious incident,” ordered a security review and urged the public to watch for scam calls and emails. The company whose access was abused had not been named when the breach was announced.
Whatever the investigation turns up, the lawyers and communications teams for Danish officials and that company should go over every word they put out, because regulators, police and reporters will. After a data breach, an organization's own statements often become some of the most valuable evidence the other side has, which makes each one a legal decision and a communications decision at the same time.
That is why legal and communications teams need to work in lockstep from the first hour, deciding together what to say and what to hold back until the facts are confirmed.
In the United States, a growing share of data breaches now end up in court. BakerHostetler's latest incident response report found that class actions followed 14% of the publicly disclosed breaches the firm handled in 2025, up from 9% in 2024, which is an increase of more than half in a single year.
What happens when a company gets those first words wrong? Just ask Instructure, the company behind the Canvas learning platform used by thousands of schools. In May, days after disclosing a breach, it described the incident as resolved. The next day, hackers defaced Canvas login pages at hundreds of schools with a message announcing they had breached the company again, and the platform went offline in the middle of final exams. Calling the breach resolved made every statement that followed harder to believe.
CEO Steve Daly apologized, writing that customers “deserved more consistent communication from us, and we didn't deliver it.” Within days, more than half a dozen class actions had been filed, with plaintiffs alleging the company promised strong data security and failed to deliver it.
The pressure to say something fast is enormous, since customers want answers, all 50 states have breach notification laws, and reporters often call within hours. The facts come together far more slowly, and IBM's latest annual study puts the average time to identify and contain a breach at 247 days, so anything said in the first week is said with only part of the picture.
Every statement, from the first customer email to the CEO's remarks to a reporter, should be read by counsel before it goes out, because plaintiffs' lawyers will read them all later. Bringing outside communications advisers in can also help navigate those messaging decisions and mitigate reputational risk.
Statements should stick to what is known, what isn't known yet, and what people should do next, which is largely what Denmark's first announcement did. Words like “contained,” “resolved” and “no evidence of misuse” can be quoted back for years if they turn out to be wrong, so they belong in a statement only once the evidence supports them.
When the way in turns out to be another company's access, as it did in Denmark, the temptation to point fingers in public is strong. Organizations are better served telling people they are sorry this happened to them, explaining what they are doing to help, and leaving the question of blame to the lawyers.
Every version of the story also has to match, because the notice letter, the website FAQ, the call center script, social media posts and anything an executive tells a reporter will eventually be laid side by side, and any gap between them can become a question in a deposition.
When an organization goes quiet, someone else fills the void, whether that is a reporter, a plaintiffs' firm or, as Canvas users saw on their login screens, the hackers themselves. No response is still a response, and it is rarely the one a company would choose.
Much of this work can be done before anything goes wrong. Companies should draft their first statements now, decide who will speak, and take a hard look at what their websites and sales materials already promise about security, because those promises have a way of showing up in complaints.
Every American who has watched a police drama knows the warning by heart: Anything you say can and will be used against you. After a data breach, the same rule applies to companies and governments alike, and the ones that come through it best keep talking, carefully and truthfully, in words that will still hold up when they are read back in court.
Evan Nierman is CEO of crisis PR firm Red Banyan and author of “Crisis Averted: PR Strategies to Protect Your Reputation and the Bottom Line.”