Denmark CPR register breach (5 Oct): names, addresses and CPR numbers of ~8.8 million registered people accessed by abusing a Danish company's lawful lookup access
Denmark's Central Person Register (CPR) administration and the Ministry of Higher Education, Research and Digitalisation announced on 5 October 2026 a serious security incident: unauthorised parties misused a Danish company's legitimate access to search the CPR system and obtained names, addresses, CPR (personal identity) numbers and other details for about 8.8 million people registered in CPR. The figure is higher than Denmark's population of roughly six million because the register also holds deceased people, people who have emigrated and others; CPR holds about 11 million records in total (TV 2). People registered with name and address protection are not included, according to the review so far. CPR staff noticed irregular activity in the system on Friday 2 October, covering a period in September; minister Christina Egelund told Ritzau the access ran for about ten days through a smaller company's account and acknowledged security failings. The company's access has been shut off, the case has been reported to the Danish Data Protection Agency (Datatilsynet), police are investigating, the parliamentary digitalisation committee has been briefed and a full security review of CPR has been ordered. The company, the attackers and how many records were actually extracted have not been named. Authorities warn people never to give out passwords or codes by phone or email, even when the caller already knows their name, address and CPR number. Separate from the DTU incident on this desk. Wire: Cybersecurity News 5 Oct.
- Product
- Det Centrale Personregister (CPR), Denmark's national civil registration system — third-party company lookup access
- Versions
- n/a — incident, no CVE
- Exploited in Australia?
- unknown
- Patch to
- Danes and anyone ever registered in Denmark: expect phishing and phone scams that quote a correct name, address and CPR number; never hand over MitID codes or passwords, and use sikkerdigital.dk or the Cyberhotline (+45 33 37 00 37). Organisations that give partners lookup access to identity registers should monitor query volume per account, rate-limit bulk searches and review dormant or low-use partner access.
Primary: Danish Ministry of Higher Education, Research and Digitalisation — Extensive unauthorised access to citizens' CPR data (5 Oct 2026, Danish) · Vendor: CPR administration — incident notice (5 Oct 2026, Danish) · Cybersecurity News — Denmark data breach exposes personal records of 8.8 million people (5 Oct 2026)
