Denmark CPR breach exposes 8.8 million personal records
Attackers misused a Danish company's legal access to the CPR register and pulled names, addresses and ID numbers of 8.8 million people in September.
3 min read

By the numbers
- people whose CPR records were accessed
- 8.8M
- of unauthorized searches in September
- ~10 days
- when the unusual activity was spotted
- Oct 2
Denmark's national register of residents, known as CPR, was searched without permission for the records of about 8.8 million people. The CPR administration announced the breach on October 5, 2026. The attackers did not break into the register itself. They misused the legal search access of a private Danish company and collected names, addresses and CPR numbers, the personal ID numbers Danes use across public and private services.
How the attackers got in
The CPR register lets approved companies look people up. One of those companies had its access abused, according to the CPR administration. The Copenhagen Post describes it as a small Danish firm. Its name has not been released because the police investigation is still running.
Officials have not said how the company's login was compromised. They have also not named the people behind the searches. The Copenhagen Post reports this timeline:
| Date (2026) | What happened |
|---|---|
| September | Unauthorized searches run for about 10 days |
| October 2 | An employee notices unusual activity |
| October 3 | The breach is confirmed |
| October 5 | The CPR administration announces it |
Who and what was exposed
The 8.8 million figure is larger than Denmark's population of about 6 million. The Copenhagen Post explains that the register also holds people who have died or moved abroad.
All the reports agree on three data fields: name, address and CPR number. A second Copenhagen Post report also lists birth dates. GBHackers says other details from the register may have been included. People who had registered name and address protection were not affected, the CPR administration says.
How Denmark is responding
The CPR administration shut off the company's access and reported the incident to Datatilsynet, Denmark's data protection authority. The police are investigating. GBHackers reports that authorities have ordered a full security review of the CPR system.
Digitalization Minister Christina Egelund said the security around the company's access was not good enough. "It is a serious incident. It should not be able to happen," she said, as quoted by the Copenhagen Post. A wire report carried by Kuwait Times quotes her calling it "an extremely serious incident."
Why the data is useful for phishing
The biggest near-term risk is fraud that looks official. Jens Myrup Pedersen, a cybersecurity expert, told the Copenhagen Post that real personal details make scam messages more convincing. "The more data you have about people, the more realistic attacks you can also create," he said.
He added that a fraudulent loan would still require more checks than this data alone can pass. GBHackers reports the official advice. Treat unexpected messages with suspicion. Never give out passwords or bank details to someone who contacts you. Use Denmark's Sikkerdigital portal and its Cyberhotline for help.
What this means for developers
Stop treating ID numbers as secrets. If your service checks identity with a name, an address and a CPR number, assume attackers now hold that set for most of Denmark. That covers password resets, support calls and account recovery. Add a factor the attacker cannot look up, such as a code sent to a device the user already owns.
Watch your partners, not just your front door. The register was not hacked directly. A partner's legitimate access was. If you run an API that other companies can query, set volume limits for each partner and alert on bulk lookups. Here, the searches ran for about 10 days before anyone noticed.
Lock down any registry or data-provider credentials you hold. Rotate them, limit which networks can use them, and log every query. A small company's login was the weak point in this breach.
Prepare your support teams for convincing fraud. A message that quotes a customer's real address and ID number is no proof that it comes from you or from the government. Tell customers how you will and will not contact them, before the scammers do.
Sources
- Omfattende uautoriseret adgang til borgeres CPR-oplysninger - CPR-administrationen
- Danish minister says security was inadequate after access to 8.8 million personal records - The Copenhagen Post
- Stolen CPR data could make phishing attacks more convincing, cybersecurity expert warns - The Copenhagen Post
- Denmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records - GBHackers
- Hackers access personal data of 8.8m people in Denmark - Kuwait Times
Related articles

Federal judge rules a Flock plate search unconstitutional
A federal judge ruled a warrantless Flock license plate search broke the Fourth Amendment and threw out 91 pounds of seized meth. It is not binding precedent.

Bitchat pulled from India's App Store and Google Play
India ordered Jack Dorsey's offline messenger Bitchat off Apple's and Google's stores under Section 69A, months after GitHub was told to remove its code.

Hans Anders pulls Ray-Ban Meta glasses over privacy
Hans Anders stopped selling Ray-Ban Meta glasses in the Netherlands and Belgium on October 2, a day after Wehkamp, as Dutch pressure on them grows.
The daily brief
Three to five stories a day, and what each one means for the people who build software. Free, no spam.