Skip to content

Denmark CPR breach exposes 8.8 million personal records

Attackers misused a Danish company's legal access to the CPR register and pulled names, addresses and ID numbers of 8.8 million people in September.

By Tech AI Wire Team

3 min read

XLinkedIn
Screenshot of the CPR administration's Danish-language announcement of the unauthorized access, dated 05-10-2026.

By the numbers

people whose CPR records were accessed
8.8M
of unauthorized searches in September
~10 days
when the unusual activity was spotted
Oct 2

Denmark's national register of residents, known as CPR, was searched without permission for the records of about 8.8 million people. The CPR administration announced the breach on October 5, 2026. The attackers did not break into the register itself. They misused the legal search access of a private Danish company and collected names, addresses and CPR numbers, the personal ID numbers Danes use across public and private services.

How the attackers got in

The CPR register lets approved companies look people up. One of those companies had its access abused, according to the CPR administration. The Copenhagen Post describes it as a small Danish firm. Its name has not been released because the police investigation is still running.

Officials have not said how the company's login was compromised. They have also not named the people behind the searches. The Copenhagen Post reports this timeline:

Date (2026)What happened
SeptemberUnauthorized searches run for about 10 days
October 2An employee notices unusual activity
October 3The breach is confirmed
October 5The CPR administration announces it

Who and what was exposed

The 8.8 million figure is larger than Denmark's population of about 6 million. The Copenhagen Post explains that the register also holds people who have died or moved abroad.

All the reports agree on three data fields: name, address and CPR number. A second Copenhagen Post report also lists birth dates. GBHackers says other details from the register may have been included. People who had registered name and address protection were not affected, the CPR administration says.

How Denmark is responding

The CPR administration shut off the company's access and reported the incident to Datatilsynet, Denmark's data protection authority. The police are investigating. GBHackers reports that authorities have ordered a full security review of the CPR system.

Digitalization Minister Christina Egelund said the security around the company's access was not good enough. "It is a serious incident. It should not be able to happen," she said, as quoted by the Copenhagen Post. A wire report carried by Kuwait Times quotes her calling it "an extremely serious incident."

Why the data is useful for phishing

The biggest near-term risk is fraud that looks official. Jens Myrup Pedersen, a cybersecurity expert, told the Copenhagen Post that real personal details make scam messages more convincing. "The more data you have about people, the more realistic attacks you can also create," he said.

He added that a fraudulent loan would still require more checks than this data alone can pass. GBHackers reports the official advice. Treat unexpected messages with suspicion. Never give out passwords or bank details to someone who contacts you. Use Denmark's Sikkerdigital portal and its Cyberhotline for help.

What this means for developers

Stop treating ID numbers as secrets. If your service checks identity with a name, an address and a CPR number, assume attackers now hold that set for most of Denmark. That covers password resets, support calls and account recovery. Add a factor the attacker cannot look up, such as a code sent to a device the user already owns.

Watch your partners, not just your front door. The register was not hacked directly. A partner's legitimate access was. If you run an API that other companies can query, set volume limits for each partner and alert on bulk lookups. Here, the searches ran for about 10 days before anyone noticed.

Lock down any registry or data-provider credentials you hold. Rotate them, limit which networks can use them, and log every query. A small company's login was the weak point in this breach.

Prepare your support teams for convincing fraud. A message that quotes a customer's real address and ID number is no proof that it comes from you or from the government. Tell customers how you will and will not contact them, before the scammers do.

Sources

  1. Omfattende uautoriseret adgang til borgeres CPR-oplysninger - CPR-administrationen
  2. Danish minister says security was inadequate after access to 8.8 million personal records - The Copenhagen Post
  3. Stolen CPR data could make phishing attacks more convincing, cybersecurity expert warns - The Copenhagen Post
  4. Denmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records - GBHackers
  5. Hackers access personal data of 8.8m people in Denmark - Kuwait Times

Related articles

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.