Denmark CPR register: misused company access exposed data on 8.8 million people
By Sethu Satheesh · 6 Oct 2026 · 12 min read
Threat Actor: Unknown · Target: Denmark's Central Person Register (CPR) / Danish public identity register
Source: ufm.dk
Executive Summary
On 5 October 2026 Denmark's Ministry of Research, Education and Digitalisation (Forsknings-, Uddannelses- og Digitaliseringsministeriet) disclosed that unauthorised parties had obtained names, addresses and CPR numbers on approximately 8.8 million people registered in the Central Person Register (Det Centrale Personregister, CPR).12 The CPR administration first noticed irregular behaviour in the system on the evening of Friday 2 October 2026, scoped it over the weekend, reported it to the Danish Data Protection Authority (Datatilsynet) on Sunday 4 October, and went public on 5 October.13
The 8.8 million figure covers living residents, people who have emigrated and deceased people — the register holds roughly 11 million records in total, so the exposure reaches about 80% of it, a number larger than Denmark's living population.145 The access did not involve any technical compromise of the CPR system. Instead, someone misused a private Danish company's lawful access to search CPR under section 38 of the CPR Act, staying within the categories of data that such companies are permitted to retrieve.1 At a press briefing on 6 October, a ministry department head, Mikkel Leihardt, said just over 14 million CPR lookups were attempted and 8.8 million returned data — described as "en høst" (a harvest) run over about ten days in September.6 The leak was detected not by a security control but because an unusually large lookup invoice was due to be sent to the small company, since each CPR query is billed.6
No actor has been identified. The ministry said it was "på nuværende tidspunkt ikke muligt" to say who was behind it, and the National Unit for Special Crime (National Enhed for Særlig Kriminalitet, NSK), which secured evidence at the company on the Saturday evening, said on 6 October it had no identification of the perpetrators and no one charged.16 NSK noted such cases are often cross-border and that it was reaching out to international police.6 Minister Christina Egelund called it "en dybt alvorlig hændelse" (a deeply serious incident), briefed the Folketing's Business and Digitalisation Committee, and ordered a thorough security review of CPR.17
The incident matters as a demonstration that a national identity register can be emptied through an authorised partner's access, without exploiting a single vulnerability, and that a decade's design decision — treating the CPR number as both an identifier and, in practice, an authenticator — is the real exposure. The Danish authority for societal security and the business lobby DI both responded by telling organisations to stop accepting a CPR number, name and address as proof of identity.86 It also sharpens how carefully the event should be described: it is a personal-data breach in the regulatory sense, but not a hack of the CPR system.
Verification of Claims
-
Claim: About 8.8 million people's names, addresses and CPR numbers were accessed. → Verified → Stated directly by the Ministry of Research, Education and Digitalisation and the CPR office on 5 October 2026, and by Datatilsynet's receipt of the breach report.123 The 8.8 million covers living, emigrated and deceased registrants out of a register of roughly 11 million.1
-
Claim: Just over 14 million CPR lookups were attempted; 8.8 million returned data. → Verified → Attributed on the record to ministry department head Mikkel Leihardt at the 6 October 2026 press briefing; the gap arises because lookups can target CPR numbers that do not exist.6
-
Claim: The CPR system itself was hacked or technically breached. → Unverified → No source establishes a technical intrusion. Every primary account describes misuse of a private company's lawful section 38 search access, within the data limits companies are permitted.1 It is a personal-data breach reported to Datatilsynet, not a compromise of CPR infrastructure.3
-
Claim: Data beyond names, addresses and CPR numbers was taken. → Partially verified → The ministry confirmed "navne, adresser, CPR-numre mv." ("names, addresses, CPR numbers etc."), leaving the "etc." open.1 Coverage listing marital status, family relations, Church of Denmark affiliation and legal guardianship reflects what the register can hold and what section 38 can cover, not confirmed per-record retrieval.9
-
Claim: No one has been identified or charged, and the attacker is unattributed. → Verified → As of 6 October 2026, the ministry said it could not say who was behind it, and NSK said it had no identification of perpetrators and no suspect charged.16
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| ~10 days in September 2026 | Unknown actor via a company's access | Just over 14 million automated CPR lookups attempted; 8.8 million returned data | 6 |
| October 2, 2026 (evening) | CPR administration | Noticed irregular behaviour in the CPR system | 1 |
| October 3–4, 2026 (weekend) | CPR administration / NSK | Scoped the access; NSK secured evidence at the company on Saturday evening | 16 |
| October 4, 2026 | CPR administration → Datatilsynet | Incident reported to the Data Protection Authority | 13 |
| October 5, 2026 | Ministry / CPR office | Public disclosure; company's access stopped; Datatilsynet opens case | 123 |
| October 6, 2026 | Ministry / NSK / Agency for Societal Security | Press briefing: 14M-lookup figure, no suspects, guidance to stop relying on CPR numbers | 6 |
Incident Anatomy
This was not an intrusion into the CPR system; it was the abuse of a legitimate data-access relationship. Reconstructable attacker tradecraft is therefore limited to how the lawful access was driven.
Access vector: a trusted third party's authorised lookup
Under section 38 of the CPR Act, private companies with a legitimate interest may retrieve CPR data on a defined set of people they have individually identified in advance (by CPR number, by date of birth and name, or by name and address), provided they are also entitled to receive the data under data-protection law.1 A single small Danish company held such access. An unauthorised party — reported by Version2 as "en bruger fra en unavngiven mindre dansk virksomhed" (a user from an unnamed small Danish company) — drove that company's lawful access to search CPR (T1199, T1078).10 Whether this was credential abuse, a compromised integration or an insider is not established publicly; police secured evidence at the company itself.6
Collection: automated harvesting within the permitted scope
The access was used to run just over 14 million CPR lookups over roughly ten days, returning data on 8.8 million registrants — names, addresses and CPR numbers (T1119, T1213).6 The queries stayed within the categories a section 38 company is allowed to pull, which is why no access-control rule was violated in a way the system would reject.1 Records belonging to people with name and address protection (navne- og adressebeskyttelse) were not returned, consistent with that company's access not extending to that part of the register.1
Detection: billing, not security monitoring
The harvest ran for about ten days without tripping a volume or anomaly alarm. It surfaced because each CPR lookup is billed and an unusually large invoice was about to be sent to the small company; that cost anomaly, not a security control, prompted the investigation that began the evening of 2 October.6 An experienced bug-bounty researcher told Version2 that automatic brakes should have engaged long before ten days elapsed.10
Loading diagram...
Threat Actor Profile
Name: Unknown Aliases: None — no group has claimed the activity and none has been named Attribution confidence: None. As of 6 October 2026 the ministry said it was not possible to say who was behind it, and NSK reported no identification and no suspect charged.16 Motivation: Unstated. The data set — names, addresses and CPR numbers at national scale — is of obvious value for identity fraud and social-engineering, and Danish authorities framed their public guidance around fraud risk.86
No technical indicators, infrastructure or actor claims have been published, which NSK cited as a reason attribution is open; it noted such cases are frequently cross-border and that it was engaging international police partners.6 The only established facts about the actor are behavioural: they obtained the use of one company's lawful CPR access and drove it as an automated harvester at a volume that normal use by that company would not explain.
MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):
| ID | Technique |
|---|---|
| T1199 | Trusted Relationship |
| T1078 | Valid Accounts |
| T1119 | Automated Collection |
| T1213 | Data from Information Repositories |
OPSEC: Unknown. No indicators were disclosed; the activity was conducted entirely through a legitimate access path, which minimised the technical footprint a defender could detect and left per-query billing as the signal that eventually exposed it.6
Technical Indicators
network_iocs: none disclosed
file_hashes: none disclosed
malware: none disclosed — no malware or exploit was involved; lawful API/search access was misused
behavioural_indicators:
- 'Anomalous volume of CPR section 38 lookups from a single authorised company (~14M attempts over ~10 days)'
- 'Lookup volume inconsistent with the company''s normal business use'
- 'Spike in per-query lookup billing for one access-holder'
affected_data_categories:
- names
- addresses
- CPR numbers
- 'additional register fields possible but unconfirmed (ministry wording: "mv."/etc.)'
note: >
No attacker IPs, domains, hashes or crypto addresses have been published by the
ministry, Datatilsynet or police as of 6 October 2026. Victim personal data
(individual CPR numbers, names, addresses) is deliberately not reproduced here.Legal and Regulatory Response
The CPR administration reported the incident to Datatilsynet on 4 October 2026; the authority confirmed on 5 October it had received the report, opened a case, and was examining what happened, how it could happen, and who is the data controller responsible — adding that it could not yet assess the specifics.13 The case is being investigated by police: the National Unit for Special Crime (NSK) said on 6 October that it had secured evidence at the company, had no identification of perpetrators and no one charged, and was reaching out to international police given the likely cross-border nature.6
The Agency for Societal Security (Styrelsen for Samfundssikkerhed), under the Ministry for Societal Security and Emergency Management, published citizen guidance warning that the exposed data could be misused for fraud and urging authorities and citizens to be alert, directing people to sikkerdigital.dk and its cyber hotline (extended hours).86 Minister Christina Egelund briefed the Folketing's Business and Digitalisation Committee, said initiatives to prevent recurrence had already been started, and ordered a thorough security review of CPR.1 No GDPR enforcement decision or fine had been issued as of 6 October 2026; the Datatilsynet case had only just opened.3
Impact Assessment
- Confirmed: Names, addresses and CPR numbers on approximately 8.8 million registrants (living, emigrated and deceased) were returned; just over 14 million lookups were attempted.16
- Confirmed: Names and addresses of people with registered name-and-address protection were not among the returned data.1
- Reported, not independently confirmed: The register can also hold marital status, birth registration, family relations, Church of Denmark affiliation and legal guardianship; whether any of these were retrieved per record is unconfirmed.9
- Estimated: The exposure reaches about 80% of the roughly 11 million CPR records — a figure larger than Denmark's living population.4511
- Unknown: The attacker's identity and motive; whether the harvested data has been retained, sold or used; and whether any affected people will be issued new CPR numbers, which the minister said on 6 October was too early to determine.6
Lessons and Defensive Recommendations
For SOC/defenders and register operators:
- Rate-limit and anomaly-detect on bulk queries to any identity register. A ten-day, 14-million-lookup harvest from one access-holder ran without tripping a control; the only backstop that fired was per-query billing.610
- Baseline each authorised partner's normal query volume and alert on deviation, rather than only checking that each individual query is permitted.
For organisations holding third-party data-access grants (section 38-type relationships):
- Treat a partner's standing data-access authorisation as a breach vector: monitor the volume and pattern of access, enforce volume caps server-side, and revoke on anomaly instead of relying on the partner's own controls.
- Protect and monitor the credentials and integrations that drive such access; assume they are a target.
For any organisation authenticating customers or staff:
- Stop treating a CPR number (or name plus address) as proof of identity. Denmark's Agency for Societal Security and DI both advised moving to MitID, control questions or portal logins after the leak, because the identifier must now be assumed to be in adversary hands.6
For leadership and policymakers:
- The decision this incident should change is architectural: an identifier used as an authenticator cannot survive a population-scale leak. The register's own abuse controls — not a partner's — are the control that failed, and a security review alone will not fix the dual role of the CPR number.1
Sources
Footnotes
-
Forsknings-, Uddannelses- og Digitaliseringsministeriet — Omfattende uautoriseret adgang til borgeres CPR-oplysninger — October 5, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24
-
CPR-kontoret (cpr.dk) — Omfattende uautoriseret adgang til borgeres CPR-oplysninger — October 5, 2026 ↩ ↩2 ↩3
-
Datatilsynet — Datatilsynet er opmærksom på sag om opslag i CPR — October 5, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Help Net Security — Data breach at Denmark's population register exposes 8.8 million people — October 6, 2026 ↩ ↩2
-
The Irish Times — Major Denmark breach exposes personal data of 8.8 million people — October 5, 2026 ↩ ↩2
-
TV 2 — Uvedkommende har fået adgang til 8,8 millioner CPR-numre (live coverage and press briefing) — October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23
-
DR — Uvedkommende har haft adgang til 8,8 millioner CPR-numre — October 5, 2026 ↩
-
Styrelsen for Samfundssikkerhed — Uvedkommende har fået adgang til borgeres CPR-oplysninger: Sådan skal du forholde dig — October 5, 2026 ↩ ↩2 ↩3
-
The Copenhagen Post — CPR data breach exposes personal details of 8.8 million people in Denmark — October 5, 2026 ↩ ↩2
-
Version2 — Erfaren hacker undrer sig: Her burde alarmen være gået i 10 dages CPR-tyveri — October 6, 2026 ↩ ↩2 ↩3
-
The Hacker News — Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account — October 6, 2026 ↩
Related Research
A threat actor advertised ~800,000 TCS employee-directory records from a wider Azure/Entra data-theft campaign; TCS told Indian exchanges on 10 August 2026 it found no credible evidence of a breach.
Clover Health (138,677) and AngMar Management Services (126,196) disclosed separate US healthcare breaches in September 2026 — one social engineering of three staff accounts, one Interlock ransomware attack — paired in coverage as '250,000 impacted'.
Two former US airmen got 111 and 78 months for a BEC and card-fraud scheme that diverted $1.68M and $720K wires. The docket shows conspiracy pleas, overlapping restitution and a pending appeal; 15 victims and $2.4M are not DOJ figures.