Skip to content

Denmark CPR register breach exposes 8.8 million people

Denmark says unauthorized searches of its Central Person Register exposed names, addresses and CPR numbers for 8.8 million people, via a private company's legitimate access.

Published 3 min read

Denmark confirmed on October 5 that unauthorized parties ran searches against the Central Person Register (CPR) and exposed personal data on roughly 8.8 million people — out of about 11 million records in the system. The exposed fields are names, addresses, and CPR numbers, the 10-digit national identifiers Danes use for banking, healthcare, and government services. People enrolled in the register's name- and address-protection scheme were not exposed.

What happened

This was not a direct intrusion into the CPR system. According to the government's statement, the attackers misused a private Danish company's legitimate access to the register, running automated searches to enumerate valid CPR numbers and pull the associated name and address data. Authorities have not said how the unauthorized parties obtained or abused that access — the initial entry point is still unknown.

The company's access has been suspended while police investigate. Officials say it is too early to attribute the activity and have named no actor.

Timeline

  • September 2026 — the unauthorized searches took place, per the investigation.
  • October 2 — the administration detected irregular activity.
  • Over the following weekend — analysis confirmed the September searches.
  • October 5 — the government disclosed the incident publicly.

Christina Egelund, the minister for research, education and digitalisation, called it "a deeply serious incident" and ordered a broad security review of the CPR system, plus extended hours for the national digital-security hotline.

What to do

For organizations that rely on CPR numbers as an identifier or weak authenticator, this breach is the action item.

  1. Stop treating a CPR number as a secret. Names, addresses, and CPR numbers for most of the country should now be assumed to be in the hands of fraudsters. Any flow that accepts a CPR number as proof of identity needs a second factor.
  2. Tighten monitoring on CPR-based onboarding and account-recovery paths — the exposed combination is exactly what's needed for synthetic-identity and account-takeover fraud.
  3. If your organization brokers CPR access to third parties, audit it now. The breach vector here was delegated, legitimate access being abused. Review who holds standing query access, rate-limit and log every lookup, and alert on bulk enumeration patterns.
  4. Warn Danish-facing users to expect targeted phishing and vishing that cites real personal details — the register data makes lures far more convincing.

Context

The breach is a textbook case of third-party access as the soft underbelly of an otherwise controlled system. The CPR register itself was not breached; a trusted integrator's credentials were the way in, and the register's design — broad, delegated, automatable query access — turned that foothold into a near-nationwide data pull. Centralized national identity systems concentrate exactly this risk: the register does not have to fall for the data to leak, it only has to trust someone who does. Expect scrutiny of how many private entities hold standing CPR query access, and under what controls.

Related stories