Attackers Exploited Legitimate Company Access to Harvest Denmark's National ID Registry
On October 5, 2026, Denmark's Ministry of Research, Education and Digitalisation disclosed that unauthorized parties had accessed the names, home addresses, and national identification numbers of roughly 8.8 million people — living residents, emigrants, and deceased individuals — held in Det Centrale Personregister (CPR), Denmark's national population register. Rather than exploiting a software vulnerability or deploying malware, the attackers abused the standing, lawful database access held by a small, unnamed Danish company under Section 38 of the Danish CPR Act, running a very high volume of automated lookups over roughly 10 days in September 2026 before the activity was caught. Digitalization Minister Christina Egelund called it "a deeply serious incident" and ordered a full security review of the system's access controls.
Incident Details
| Attribute | Value |
|---|---|
| Disclosure date | October 5, 2026 |
| Affected system | Det Centrale Personregister (CPR) — Denmark's national population register |
| Records exposed | ~8.8 million people (register holds ~11 million total records) |
| Data types exposed | Full name, home address, 10-digit CPR (national ID) number |
| Access vector | Legitimate third-party lookup access under CPR Act Section 38, held by a small Danish company |
| Attack window | Approximately 10 days in September 2026 |
| Detected | October 2, 2026, by a CPR administration employee |
| Regulator notified | Danish Data Protection Agency (Datatilsynet), October 4, 2026 |
| Investigating bodies | Danish Police, Datatilsynet |
| Responsible minister | Christina Egelund, Minister of Research, Education and Digitalisation |
| Excluded population | Individuals already under Denmark's name-and-address protection scheme |
How It Worked
A Trusted Third Party, Not a Software Flaw
Section 38 of the Danish CPR Act allows private companies with a "justified interest" — banks, insurers, debt collectors, and similar firms that already have a business relationship with an individual — to query CPR directly for that person's name, address, and CPR number. This is a routine, legally sanctioned channel used by thousands of Danish businesses every day. According to the ministry and Datatilsynet, the attackers did not breach CPR's own infrastructure. Instead, they gained control of or misused the account belonging to one small company that already held this standing lookup privilege, then used it as their entry point into the register.
Automated, High-Volume Number Harvesting
A Danish CPR number is a 10-digit identifier: the first six digits encode a person's date of birth (DDMMYY) and the remaining four are a serial/control sequence, of which roughly 10,000 combinations are possible for any given birth date. Datatilsynet said in its October 5 notice that "a very large number of automated lookups" were made through the compromised account to identify valid CPR numbers at scale. Authorities have not confirmed whether the attackers systematically enumerated every possible serial combination, but the sheer volume of queries — far beyond what a single small company would need for its normal business — is what ultimately exposed the activity. Notably, the queries stayed within the data fields a company is legally permitted to retrieve, which let the abuse blend in with legitimate traffic for days.
Detection and Escalation
An employee of the CPR register's administration noticed unusual query activity on Friday, October 2, 2026. Over the following weekend, the administration worked to determine the scope of the access and confirmed that it had been ongoing for about 10 days during September. Datatilsynet was formally notified on Sunday, October 4, the implicated company's access to CPR was suspended, and the breach was disclosed publicly on Monday, October 5. Police have opened an investigation, and authorities say it is too early to determine who was behind the activity or whether the company's account was compromised externally or misused from within.
Impact Assessment
| Impact Area | Description |
|---|---|
| Identity theft and fraud risk | CPR numbers function as Denmark's master identifier across tax, banking, and healthcare systems; combined with a verified name and address, they materially raise the risk of impersonation, account takeover, and convincing phishing or vishing attempts |
| Scope beyond the living population | 8.8 million records exceeds Denmark's population of roughly 6 million because CPR retains data on emigrants and deceased individuals, whose identifiers can still be repurposed for synthetic-identity fraud |
| Protected individuals unaffected | People already enrolled in Denmark's name-and-address protection scheme were excluded from the exposure |
| Institutional trust | Described as the largest known breach of CPR data in the register's history, raising scrutiny of how the thousands of companies with Section 38 access are vetted and monitored |
| Regulatory and legal exposure | Datatilsynet's investigation could produce findings against both the CPR administration and the implicated company; a parallel police investigation is examining potential criminal conduct |
| Government response cost | A government-wide security review of CPR access controls has been ordered, with Minister Egelund briefing Parliament's Business and Digitalisation Committee |
Recommendations
For the CPR Administration and Danish Government
- Audit every Section 38 account for anomalous query volume and velocity — the scale of lookups, not their content, was what eventually exposed this intrusion
- Implement real-time rate-limiting and anomaly detection on the CPR lookup interface rather than relying on manual observation
- Require stronger authentication (hardware-backed MFA) for any account with standing bulk-lookup privileges
- Introduce periodic re-certification of "justified interest" status for companies holding long-term access, rather than a one-time approval
For Companies Holding Section 38 or Similar Registry Access
- Immediately review internal account access logs, credential hygiene, and shared-account practices for any sensitive government lookup integration
- Rotate credentials and API keys used to query CPR or equivalent registries, and enforce least-privilege scoping per employee or system
- Build internal alerting for unusual spikes in outbound lookup volume against regulated data sources
For Danish Residents
- Enroll in the fraud/credit warning service available through borger.dk if not already registered
- Treat any unsolicited call or email that cites your name, address, or CPR number as potential evidence of fraud, not proof of legitimacy — never share passwords or confidential details, even with a caller who already seems to know personal information
- Monitor bank accounts and public-sector portal logins for unauthorized activity in the coming months
- Residents eligible for name-and-address protection should consider applying, given it shielded affected individuals in this incident
For Security Teams (Third-Party Risk)
- Treat standing, "trusted" access grants to sensitive registries as a primary attack surface, equal in priority to external perimeter defenses
- Deploy automated anomaly detection on any API or portal that grants bulk lookup rights to third parties, keyed on query volume rather than query legality alone
- Maintain continuous, auditable visibility into who holds privileged lookup access to sensitive systems — not just at onboarding, but on an ongoing basis
Key Takeaways
- Denmark's CPR breach exposed names, addresses, and national ID numbers for 8.8 million people — roughly 80% of all register records — reportedly the largest data breach in Danish history.
- The attackers used no malware, phishing, or software exploit; they abused legitimate, standing third-party access granted under the CPR Act, underscoring third-party and vendor access as a major attack surface for government data.
- The 8.8 million figure exceeds Denmark's population of about 6 million because CPR retains records on emigrated and deceased individuals, who remain exposed to downstream fraud risk.
- The intrusion ran for roughly 10 days before a very large number of automated lookups tipped off CPR administration staff, highlighting the need for real-time anomaly detection on registry lookup APIs.
- Minister Christina Egelund has ordered a full security review of CPR access controls and acknowledged that safeguards around this kind of third-party access "had not been solid enough."
- Affected residents should register for borger.dk's fraud warning service and treat any contact referencing their personal data with suspicion, since the stolen information can itself be used to make phishing and impersonation attempts more convincing.