Denmark Confirms Breach of Central Person Register Affecting 8.8 Million People
Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized individuals abused a private domestic company's legitimate access to the country's Central Person Register (CPR) — the national database that assigns every resident a lifelong, 10-digit identification number used for healthcare, banking, taxation, and government services. Christina Egelund, the minister for research, education and digitalisation, disclosed the incident on Monday, October 5, 2026, calling it "a deeply serious incident" and ordering a broad security review of the system. Authorities said irregular activity was first detected on Friday, October 3, and weekend investigation work determined the unauthorized querying had been occurring since September 2026.
Details
| Attribute | Value |
|---|---|
| Disclosed | October 5, 2026 (Minister Christina Egelund) |
| Affected System | Central Person Register (CPR) — Denmark's national civil registration database |
| People Affected | Approximately 8.8 million (of roughly 11 million total records) |
| Denmark's Actual Population | Just over 6 million residents |
| Data Exposed | Full names, home addresses, and 10-digit CPR numbers |
| Attack Vector | Abuse of a legitimate domestic company's authorized API/system access |
| Attack Method | Large volume of automated searches to identify valid CPR numbers |
| Activity Window | Since at least September 2026 |
| Detected | Friday, October 3, 2026 |
| Reported to DPA | Sunday, October 4, 2026 |
| Attribution | Unknown — too early to determine, per authorities |
| Regulatory Involvement | Danish Data Protection Agency (Datatilsynet); case referred to police |
How It Happened
A Trusted Access Path, Abused
Unlike a traditional external intrusion, the CPR breach did not involve defeating a firewall or exploiting a software vulnerability in the register itself. Instead, unidentified individuals exploited an unnamed Danish company's existing, legitimate access to the CPR system — access the company would normally use for routine, authorized lookups as part of its business operations. Because the queries came through a channel that already had standing permission to search the register, they did not immediately trigger the kind of alerting that would flag an unauthenticated attacker probing the system from outside.
Automated Enumeration at Scale
Denmark's Data Protection Agency (Datatilsynet), which was notified of the incident on Sunday, October 4, described the activity as "a very large number of automated searches" run against the CPR system with the apparent goal of systematically identifying valid CPR numbers. Because Danish CPR numbers begin with a person's date of birth followed by a sequence digit, and are issued to a population whose demographic structure is well understood, large-scale automated querying can be used to enumerate and confirm which numbers correspond to real, currently or formerly registered individuals — effectively validating a dataset of names, addresses, and IDs against the authoritative government source.
Why the Exposure Touches More People Than Denmark Has Residents
The CPR register does not only hold records for Denmark's roughly 6 million current residents. It also retains entries for people who have died or emigrated, bringing the total register to approximately 11 million records. The confirmed exposure of 8.8 million people spans current residents as well as these historical entries, meaning the breach's reach extends well beyond the country's living population. Officials noted that individuals with a legally protected or secret address were not affected by the exposure.
Containment and Investigation
Once the irregular activity was identified, the company's access to the CPR system was blocked while the matter is investigated by police. As of disclosure, authorities said it was too early to determine who was responsible for the automated querying or what the end use of the harvested data might be.
Impact Assessment
| Impact Area | Description |
|---|---|
| Personal Data Exposure | Names, home addresses, and lifelong CPR numbers exposed for 8.8 million people |
| Identity Fraud Risk | CPR numbers are used across healthcare, banking, and government services and cannot easily be changed, creating long-tail exposure risk |
| Phishing / Social Engineering | Officials specifically warned that callers citing a victim's name, address, or CPR number should not be assumed legitimate |
| Scope of Population | Exposure includes deceased and emigrated individuals, not just current residents, complicating notification efforts |
| Institutional Trust | Renewed scrutiny of third-party access controls to core national identity infrastructure |
| Attribution / Motive | Unknown at time of disclosure — police investigation ongoing |
| Regulatory Exposure | Formal referral to the Danish Data Protection Agency and police increases likelihood of enforcement action against the implicated company |
Recommendations
For Danish Residents
- Treat any unsolicited phone call, text, or email that references your name, address, or CPR number with suspicion — attackers may already hold this data and use it to appear credible.
- Never share passwords, one-time codes, or banking credentials in response to an inbound call or message, regardless of how much personal detail the caller already has.
- Contact the digital security hotline (+45 33 37 00 37, operating extended hours of 8 a.m. to midnight in the days following disclosure) or visit sikkerdigital.dk for official guidance.
- Monitor bank accounts, NemID/MitID logins, and government service portals (e.g., borger.dk) for unfamiliar activity in the weeks following this disclosure.
For Organizations with CPR-Linked Access
- Audit every third-party integration or company that holds standing, authorized access to CPR lookups, and review whether query volume and patterns are actively monitored for anomalies.
- Implement rate limiting and behavioral anomaly detection on bulk or sequential lookups against government identity systems — a legitimate business use case rarely requires the volume of automated searches described here.
- Treat "trusted access abuse" as a distinct threat model from external compromise; access reviews should assume an authorized credential can be misused by an insider, a compromised partner, or a hijacked integration.
For Security Teams Generally
- Revisit logging and alerting thresholds for any system that grants standing API or bulk-query access to partners — detection in this case relied on noticing irregular activity, not a breach alert from the access layer itself.
- Where identifiers (like CPR numbers) are structured and predictable (e.g., embedding date of birth), assume they are enumerable and design validation/lookup services to resist automated guessing regardless of who holds the access credential.
- Build incident playbooks that account for exposure spanning deceased or inactive records, which complicates standard breach-notification processes built around current, living data subjects.
Key Takeaways
- Denmark disclosed on October 5, 2026 that unauthorized individuals abused a private company's legitimate access to the Central Person Register (CPR), exposing names, addresses, and CPR numbers for approximately 8.8 million people.
- The breach was not a traditional intrusion — it exploited standing authorized access rather than a vulnerability in the register itself, via a high volume of automated searches aimed at identifying valid CPR numbers.
- Unauthorized activity had reportedly been occurring since September 2026 before detection on October 3 and disclosure two days later.
- The CPR register's roughly 11 million total records include deceased and emigrated individuals, which is why the exposure figure (8.8 million) exceeds Denmark's living population of about 6 million.
- The implicated company has been blocked from the system, and the case has been referred to both the Danish Data Protection Agency and police; attribution and motive remain undetermined.
- Officials are urging residents to be especially wary of phishing and social-engineering attempts that reference personal details, since CPR numbers are permanent and cannot be reissued like a password.