Denmark CPR register breach exposes 8.8 million people
Unauthorized parties abused a Danish company's lawful CPR lookup access to pull names, addresses and CPR numbers for 8.8 million people over roughly ten days in September.
Denmark's Central Person Register (CPR) was queried for the personal data of 8.8 million people after unauthorized parties abused a private company's lawful lookup access. The CPR administration, part of the Ministry of Research, Education and Digitalisation, says the exposed records include names, addresses and CPR numbers — Denmark's lifelong national identification number — and cover living residents, people who have emigrated and the deceased. That is roughly four in five of the register's ~11 million records.
This is a credential/access-abuse incident, not a software vulnerability: there is no CVE. A legitimate integration was turned against the register.
What happened
A Danish company held sanctioned access to run CPR lookups. According to the CPR administration, unauthorized parties used that access to query the register systematically for about ten days in September 2026. The administration became aware the evening of Friday 2 October, blocked the company's access, and notified Denmark's data protection authority, Datatilsynet, on Sunday 4 October. The ministry has not named the company.
The two running figures to watch:
- 8.8 million people whose CPR data was pulled.
- ~10 days the abusive querying ran before detection.
Attribution and investigation
No actor has been identified and no group has claimed responsibility. Danish police are investigating, and Datatilsynet is examining the case. The ministry has not said how the unauthorized parties obtained or used the company's access — whether through compromised credentials, a misused API integration, or insider involvement. Minister Christina Egelund called it "a deeply serious incident" and acknowledged that safeguards around this kind of third-party access "had not been solid enough."
Reporting is based on the CPR administration's statement and Danish government comments, relayed by The Copenhagen Post and Help Net Security. Datatilsynet had not published a formal decision at the time of writing.
What to do today
The CPR number is not a secret in the way a password is — it appears on countless forms — but en-masse exposure fuels identity fraud and targeted phishing. If you operate services in Denmark:
- Review third-party CPR lookup integrations. Any partner with sanctioned register access is now a modeled threat. Audit which vendors can query, how, and whether volume limits and anomaly alerting exist.
- Rate-limit and log every lookup. Ten days of bulk querying went unnoticed; per-account query baselines and alerting on volume spikes would have cut detection time.
- Treat CPR numbers as attacker-known. Do not use a CPR number alone as an authentication factor. If any flow treats "knows the CPR number" as proof of identity, change it.
- Brief fraud and support teams to expect a rise in CPR-backed social engineering against Danish customers.
Context
National identity registers are high-value precisely because the data is authoritative and permanent — you cannot rotate a CPR number the way you rotate a password. The failure mode here is familiar: not a breached perimeter but an abused integration, where a legitimate downstream party's access became the attacker's. The volume — 8.8 million of ~11 million records — makes this one of the broadest exposures of Danish personal data to date, and a reminder that access granted to partners is access an attacker can inherit.