Denmark CPR access abuse exposed about 8.8 million people
Unauthorized searches through a Danish company's lawful CPR access exposed names, addresses, and ID numbers for about 8.8 million people.
Denmark disclosed on October 5, 2026, that unauthorized parties misused an unnamed Danish company's lawful access to the Central Person Register, rather than breaking into government systems directly, to obtain names, addresses, and CPR numbers used for healthcare, banking, taxes, and public services. Most outlets put the exposure at about 8.8 million people, including deceased people, former residents, and people living abroad—above Denmark's roughly 6 million residents because the register holds about 11 million records—while TechCrunch said about 8 million, and sources disagree on whether the data was stolen or merely returned by searches. The lookups ran for about 10 days in September 2026, with CSO Online reporting more than 14 million searches; irregular activity was detected on October 2, The Record said the Data Protection Agency was notified Sunday, and people with name-and-address protection were excluded. Most reports say the company's access was then revoked, blocked, or suspended, but Security Affairs said it had not yet been revoked. Police, including the National Special Crime Unit, and Datatilsynet are investigating; who is responsible, how the company's systems were compromised, whether the data was retained, and whether new CPR numbers will be issued remain unknown. Research and digitalisation minister Christina Egelund called it serious, ordered a broad security review—GBHackers said Parliament ordered one—and extended the national digital-security hotline, while officials warn of phishing and fraud and recommend MitID, two-factor authentication, one-time codes, or a credit warning instead of a CPR number alone.
- About 8.8 million people had names, addresses, and CPR numbers exposed via Denmark's Central Person Register; TechCrunch said about 8 million, and sources disagree on whether the data was stolen or only accessed.
- Attackers misused an unnamed Danish company's lawful CPR search access for about 10 days in September 2026; CSO Online reported more than 14 million searches.
- Irregular activity was detected on October 2, 2026 (The Record called detection Friday); authorities publicly disclosed the incident on October 5, and The Record said Datatilsynet was notified Sunday.
- The register holds about 11 million records, including deceased people, former residents, and people abroad, versus roughly 6 million residents; name-and-address-protected records were excluded.
- Most reports say the company's access was revoked, suspended, or blocked; Security Affairs said it had not yet been revoked.
- Police, including the National Special Crime Unit, and Datatilsynet are investigating; the actor, how the company was compromised, whether data was retained, and whether new CPR numbers will be issued remain unknown.
- Minister Christina Egelund ordered a security review and extended the national digital-security hotline; GBHackers said Parliament ordered a review.
- Officials warn of phishing and fraud and advise MitID, two-factor authentication, one-time codes, or a credit warning rather than relying on a CPR number alone.
Coverage timelineoldest first · each row is one article
- · 5d agoDenmark Data Breach Exposes 8.8M People's Personal Data
Hacker News · security· 92
Denmark's CPR register says attackers abused a company's access and copied data on about 8.8 million people.
- · 5d agoDenmark Data Breach Exposes Personal Records of 8.8 Million People
Cyber Security News· 90
Denmark says unauthorized access exposed names, addresses, and CPR numbers for about 8.8 million people.
- · 5d agoDenmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records
GBHackers· 90
Denmark confirmed unauthorized CPR searches exposed names, addresses, and ID numbers of about 8.8 million people.