Hackers carried out a cyberattack on Denmark's CPR system
Assessment
Rescana and similar coverage framed the event as a 'cyberattack' on CPR. No primary source establishes any technical intrusion of the CPR system. The ministry, the CPR office and Datatilsynet all describe misuse of a private company's lawful section 38 search access, used to run automated lookups within the data categories companies may retrieve. It is a personal-data breach reported to the regulator, but the register's infrastructure was not compromised and no actor is identified, so 'cyberattack/hack of the system' overstates what the record shows.
Where this claim appeared
Rescana · 2026-10-06
https://www.rescana.com/post/denmark-central-person-register-cpr-breach-cyberattack-exposes-data-of-8-8-million-via-company-account-in-2026What “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
Denmark CPR register: misused company access exposed data on 8.8 million peopleThink this assessment is wrong? Report an error.