NEWS

Data Breach at Denmark's National Population Register Exposes 8.8 Million People

Hackers abused a Danish firm's legitimate access to mass-query Denmark's CPR register, exposing names, addresses and ID numbers of 8.8M people.

Dylan H.

News Desk

October 5, 2026
7 min read
Data Breach at Denmark's National Population Register Exposes 8.8 Million People

Denmark Confirms Breach of Central Person Register Affecting 8.8 Million People

Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized individuals abused a private domestic company's legitimate access to the country's Central Person Register (CPR) — the national database that assigns every resident a lifelong, 10-digit identification number used for healthcare, banking, taxation, and government services. Christina Egelund, the minister for research, education and digitalisation, disclosed the incident on Monday, October 5, 2026, calling it "a deeply serious incident" and ordering a broad security review of the system. Authorities said irregular activity was first detected on Friday, October 3, and weekend investigation work determined the unauthorized querying had been occurring since September 2026.


Details

AttributeValue
DisclosedOctober 5, 2026 (Minister Christina Egelund)
Affected SystemCentral Person Register (CPR) — Denmark's national civil registration database
People AffectedApproximately 8.8 million (of roughly 11 million total records)
Denmark's Actual PopulationJust over 6 million residents
Data ExposedFull names, home addresses, and 10-digit CPR numbers
Attack VectorAbuse of a legitimate domestic company's authorized API/system access
Attack MethodLarge volume of automated searches to identify valid CPR numbers
Activity WindowSince at least September 2026
DetectedFriday, October 3, 2026
Reported to DPASunday, October 4, 2026
AttributionUnknown — too early to determine, per authorities
Regulatory InvolvementDanish Data Protection Agency (Datatilsynet); case referred to police

How It Happened

A Trusted Access Path, Abused

Unlike a traditional external intrusion, the CPR breach did not involve defeating a firewall or exploiting a software vulnerability in the register itself. Instead, unidentified individuals exploited an unnamed Danish company's existing, legitimate access to the CPR system — access the company would normally use for routine, authorized lookups as part of its business operations. Because the queries came through a channel that already had standing permission to search the register, they did not immediately trigger the kind of alerting that would flag an unauthenticated attacker probing the system from outside.

Automated Enumeration at Scale

Denmark's Data Protection Agency (Datatilsynet), which was notified of the incident on Sunday, October 4, described the activity as "a very large number of automated searches" run against the CPR system with the apparent goal of systematically identifying valid CPR numbers. Because Danish CPR numbers begin with a person's date of birth followed by a sequence digit, and are issued to a population whose demographic structure is well understood, large-scale automated querying can be used to enumerate and confirm which numbers correspond to real, currently or formerly registered individuals — effectively validating a dataset of names, addresses, and IDs against the authoritative government source.

Why the Exposure Touches More People Than Denmark Has Residents

The CPR register does not only hold records for Denmark's roughly 6 million current residents. It also retains entries for people who have died or emigrated, bringing the total register to approximately 11 million records. The confirmed exposure of 8.8 million people spans current residents as well as these historical entries, meaning the breach's reach extends well beyond the country's living population. Officials noted that individuals with a legally protected or secret address were not affected by the exposure.

Containment and Investigation

Once the irregular activity was identified, the company's access to the CPR system was blocked while the matter is investigated by police. As of disclosure, authorities said it was too early to determine who was responsible for the automated querying or what the end use of the harvested data might be.

Impact Assessment

Impact AreaDescription
Personal Data ExposureNames, home addresses, and lifelong CPR numbers exposed for 8.8 million people
Identity Fraud RiskCPR numbers are used across healthcare, banking, and government services and cannot easily be changed, creating long-tail exposure risk
Phishing / Social EngineeringOfficials specifically warned that callers citing a victim's name, address, or CPR number should not be assumed legitimate
Scope of PopulationExposure includes deceased and emigrated individuals, not just current residents, complicating notification efforts
Institutional TrustRenewed scrutiny of third-party access controls to core national identity infrastructure
Attribution / MotiveUnknown at time of disclosure — police investigation ongoing
Regulatory ExposureFormal referral to the Danish Data Protection Agency and police increases likelihood of enforcement action against the implicated company

Recommendations

For Danish Residents

  • Treat any unsolicited phone call, text, or email that references your name, address, or CPR number with suspicion — attackers may already hold this data and use it to appear credible.
  • Never share passwords, one-time codes, or banking credentials in response to an inbound call or message, regardless of how much personal detail the caller already has.
  • Contact the digital security hotline (+45 33 37 00 37, operating extended hours of 8 a.m. to midnight in the days following disclosure) or visit sikkerdigital.dk for official guidance.
  • Monitor bank accounts, NemID/MitID logins, and government service portals (e.g., borger.dk) for unfamiliar activity in the weeks following this disclosure.

For Organizations with CPR-Linked Access

  • Audit every third-party integration or company that holds standing, authorized access to CPR lookups, and review whether query volume and patterns are actively monitored for anomalies.
  • Implement rate limiting and behavioral anomaly detection on bulk or sequential lookups against government identity systems — a legitimate business use case rarely requires the volume of automated searches described here.
  • Treat "trusted access abuse" as a distinct threat model from external compromise; access reviews should assume an authorized credential can be misused by an insider, a compromised partner, or a hijacked integration.

For Security Teams Generally

  • Revisit logging and alerting thresholds for any system that grants standing API or bulk-query access to partners — detection in this case relied on noticing irregular activity, not a breach alert from the access layer itself.
  • Where identifiers (like CPR numbers) are structured and predictable (e.g., embedding date of birth), assume they are enumerable and design validation/lookup services to resist automated guessing regardless of who holds the access credential.
  • Build incident playbooks that account for exposure spanning deceased or inactive records, which complicates standard breach-notification processes built around current, living data subjects.

Key Takeaways

  1. Denmark disclosed on October 5, 2026 that unauthorized individuals abused a private company's legitimate access to the Central Person Register (CPR), exposing names, addresses, and CPR numbers for approximately 8.8 million people.
  2. The breach was not a traditional intrusion — it exploited standing authorized access rather than a vulnerability in the register itself, via a high volume of automated searches aimed at identifying valid CPR numbers.
  3. Unauthorized activity had reportedly been occurring since September 2026 before detection on October 3 and disclosure two days later.
  4. The CPR register's roughly 11 million total records include deceased and emigrated individuals, which is why the exposure figure (8.8 million) exceeds Denmark's living population of about 6 million.
  5. The implicated company has been blocked from the system, and the case has been referred to both the Danish Data Protection Agency and police; attribution and motive remain undetermined.
  6. Officials are urging residents to be especially wary of phishing and social-engineering attempts that reference personal details, since CPR numbers are permanent and cannot be reissued like a password.

Sources