Cyber & AI intelligence
Wasteland.
Briefs indexed3013
Issues30
Published Mondays07:30 CT
▣ Breach DENMARK-CPR-REGIST 2026-10-05

Denmark CPR Register: Abused Third-Party Access Exposes 8.8M Records

"Danish authorities have confirmed that unknown actors used a Danish company's lawful search access to the Central Person Register (CPR), the country's national civil registration system, to reach names, addresses, CPR…"

Danish authorities have confirmed that unknown actors used a Danish company's lawful search access to the Central Person Register (CPR), the country's national civil registration system, to reach names, addresses, CPR numbers and other data for about 8.8 million registered people. The Ministry of Research, Education and Digitalisation announced the incident on Monday, 5 October 2026, and called it "a serious security incident." The 8.8 million figure is the same across every report available. Danish outlets B.T. and Politiken describe it as "just under nine million." It does not count only current residents. It covers living residents, people who have moved abroad and people who have died, out of roughly 11 million records in the register. Note on sourcing: none of the sources for this brief is a primary document. Every one reports or quotes the ministry's statement, so the details below are attributed to those reports.

What Happened

According to the ministry's statement as reported by The Copenhagen Post, Ekstra Bladet, B.T. and Politiken, the unauthorized parties did not break into the CPR directly. They misused a Danish company's legitimate permission to run searches against the register. The CPR administration has blocked that company's access. Neither the company nor any suspects have been named.

Timeline as reported:

Ekstra Bladet reports that the incident has been reported to Datatilsynet and that police are investigating with the relevant authorities. Streamline Feed adds that the regulator says it cannot yet assess exactly what happened or who was responsible.

What Was Taken

The ministry confirms that names, addresses and CPR numbers were exposed, plus unspecified "other" data. The CPR can also hold:

The ministry has not said which of these additional fields were accessed for each person (The Copenhagen Post).

Access versus exfiltration: Many headlines (Ekstra Bladet, Computerworld) describe the data as "leaked." The official wording is "access." Egelund told TV 2 that, because of the investigation, she cannot say how much of the data was actually extracted from the system. Readers should treat the volume taken as unconfirmed.

Protected individuals: According to the review so far, people registered with name and address protection were not exposed (The Copenhagen Post, Ekstra Bladet).

Number reissuance: When TV 2 asked whether Danes would need new CPR numbers, Egelund said it was "too early" to say.

Why It Matters

The CPR number is the key identifier across Danish public and private services, including healthcare, banking, tax and MitID-linked workflows. A CPR number also encodes the person's date of birth. ESET security expert Leif Jensen told Ekstra Bladet he cannot recall a larger leak from a Danish public authority. He called it "completely unacceptable" and warned that criminals value birth dates because they help target older people. Security expert John Foley told Politiken that "only imagination sets the limits" on how the data could be misused.

Egelund told TV 2 that security had "obviously" not been adequate: "If it had been, this would not have happened." She warned citizens to expect phishing and to treat unexpected contact, unfamiliar links and requests for personal details with more suspicion than usual. She also directed them to sikkerdigital.dk.

For defenders, the main lesson is that the breach path was authorized third-party access, not a perimeter compromise. Government registers and other high-value data sources often grant broad query rights to private companies. Each of those integrations is a large-scale extraction channel if its controls, monitoring or credentials fail.

The Attack Technique

Authorities have confirmed only that a company's lawful CPR search access was misused. Streamline Feed reports that the 4 October notification to the regulator described "a very large number of automated searches aimed at identifying valid CPR numbers." That would be enumeration through the search interface. Only that one outlet reports this detail, and it describes the notification under investigation, not a final finding. Treat it as unconfirmed.

Still unknown, as Streamline Feed also notes: whether the access came through stolen credentials, an insider, or a software weakness in the company's or CPR's integration. The minister's comment that similar access through other companies has also been closed points to a systemic control gap rather than a single compromised account. That reading is our inference, not a confirmed finding.

What Organizations Should Do

  1. Inventory and audit third-party query access to sensitive registers and core data stores. Check who holds search rights, how wide those rights are, and whether the business still needs them.
  2. Enforce volume and pattern limits on lookup APIs. Use rate limits, per-client quotas and alerts on sequential or high-failure query patterns. Enumeration of valid identifiers should trigger alerts within hours, not after weeks.
  3. Bind partner access to strong authentication. Use certificate-based or hardware-backed credentials, IP allowlisting and short-lived tokens, so that a stolen credential cannot be reused at scale.
  4. Prepare for CPR-themed phishing and fraud. Danish organizations, banks especially, should expect social engineering that uses accurate names, addresses and birth dates. Update caller verification so it does not rely on CPR numbers or addresses as proof of identity.
  5. Stop treating CPR numbers as secrets. Any workflow that authenticates a person by CPR number, or by CPR number plus address, should be considered weakened and moved to MitID or other strong factors.
  6. Monitor for the dataset appearing on criminal forums and paste sites. Prepare customer communications in case extraction is confirmed.

Sources: CPR data breach exposes personal details of 8.8 million people in D... | CPR-numre kompromitteret - TV 2 | 8,8 millioner borgeres CPR-oplysninger lækket: - Dybt alvorligt – E... | Uvedkommende har fået adgang til 8,8 millioner CPR-numre i Danmark... | Uvedkommende har skaffet sig adgang til CPR-oplysninger på millione... | Denmark Probes Unauthorised CPR Access Affecting 8.8m Registered Pe... | Ekspert kalder læk det største nogensinde: 'Fuldstændigt uacceptabe... | Kæmpe databrud: Millioner af danskere har fået lækket personoplysni...