Denmark CPR Breach Exposed 8.8 Million Through One Firm

Intruders used a small Danish company's lawful CPR lookup access for ten days in September, reaching names, addresses and CPR numbers of 8.8 million people.

Trust the Identity, Limit the Reach
  • October 8, 2026

Attackers gained access to the names, addresses and CPR numbers of about 8.8 million people from Denmark’s national population register in September. The access ran through a small Danish company that had a lawful right to search the Central Person Register (CPR). It lasted about ten days, and the register only noticed on October 2.

Denmark’s ministry for research, education and digitalisation announced the incident on October 5, 2026. The register’s administration has shut off the company’s access, notified the data protection authority Datatilsynet and brought in the police. Who carried it out, and how they got hold of the company’s access, is still unknown.

What is the Danish CPR register? The Central Person Register is Denmark’s national population register. Since 1968 it has recorded everyone who lives or has lived in Denmark, and each person carries a 10-digit CPR number. Public bodies and companies with a legitimate interest use it to look up names and addresses.

Ten Days of Lookups Through One Company’s Access

An employee at the CPR administration spotted the unusual activity on the evening of Friday, October 2. On Saturday a clearer picture emerged that this was a security incident. Over the weekend, the administration then established how many people the lookups had reached.

Datatilsynet received the register’s notification on Sunday, October 4. That notification describes a very large number of automated lookups made to identify valid CPR numbers. The authority describes the numbers as allegedly retrieved and says it cannot yet assess the case.

What the 8.8 Million Figure Covers

This 8.8 million count covers registered people rather than current residents. It includes the living, the dead and people who have moved abroad. The register holds about 11 million people in all, while Denmark has roughly six million inhabitants. So the lookups reached about four in five entries.

Names, addresses and CPR numbers are among the exposed data. People registered with name-and-address protection are an exception, since the access did not include their names and addresses. The ministry has not said whether the lookups also reached their CPR numbers.

A Number That Identifies, Not Authenticates

ThreatLabs Background – What the Danish CPR Register Holds, and Who Can See It
Register
CPR

Det Centrale Personregister. Denmark’s central population register. It has recorded everyone who lives or has lived in Denmark since 1968.

Identifier
CPR number

A 10-digit personal number. The first six digits are the date of birth; the last four are a serial number, and the final digit is even for women and odd for men.

Authority
CPR administration

The public body that runs the register and decides which organizations may look people up in it.

Protection Status
Name-and-address protection

A status that, in most cases, stops the register from giving a person’s name and address to private companies or individuals.

Register Marker
Credit warning

Kreditvarsel. A marker in the CPR asking companies to take extra care before granting loans or credit in that person’s name. Anyone aged 15 or over can set one on borger.dk.

Regulator
Datatilsynet

Denmark’s data protection authority, which supervises how personal data is handled under GDPR.

Registered people About 11 million, including the living, people who have moved abroad and the dead
Beyond names and addresses Civil status, birth registration details, family relationships, national church membership, citizenship and guardianship information
Who can receive data Private companies with a legitimate interest, for a defined group of people they have already identified one by one
What companies typically receive Current name and address (unless protected), plus details such as a death, a move abroad or a credit warning
Legal requirement A lawful basis under GDPR and Danish data protection law
Common belief What is actually true
A CPR number is a secret code. It helps tell people apart, but official guidance says it must not be used as the only proof of identity.
The register covers Denmark’s residents. It holds about 11 million entries for a country of roughly 6 million, because the dead and emigrants stay on it.
Someone who knows your name, address and CPR number must be legitimate. Danish authorities and industry now advise extra checks such as MitID, security questions or a call back to an official number.
A CPR number can never be changed. The CPR Act already allows a new number in special cases where a person’s number has been misused.

Lookups Aimed at Finding Valid CPR Numbers

A CPR number has 10 digits. The first six give the date of birth, while the last four form a serial number whose final digit is even for women and odd for men. That leaves at most 10,000 possible numbers for any single birth date.

Under Section 38 of Denmark’s CPR Act, a company with a legitimate interest can receive register data on a larger, defined group of people. The company must first identify each person individually, by CPR number, by date of birth and name, or by name and address. It also needs a right to the data under GDPR and Danish data protection law.

The notification is clear about their purpose, which was to find valid numbers. A rule written around people a company already knows did not keep one company’s access from covering most of the register.

The Minister Says the Alarms Should Have Gone Off

The National Unit for Special Crime (NSK) has opened a high-priority investigation. Egelund has briefed two parliamentary committees, Business and Digitalisation as well as Foreign Affairs and Defence. She kept some details back for the sake of the investigation and has not ruled out an international link.

Several parties in parliament demanded a full review. Sophie Løhde, political spokesperson for the Liberal party Venstre, called the ten-day window an aggravating circumstance. In her view, Denmark has been too slow to notice unauthorized access to its citizens’ CPR data.

Lawful Access Became the Way In

To the register, each query came through a company’s lawful access. How the intruders obtained that access is still unknown. By the minister’s own account, the gap sat in the safeguards around this type of access, and in alarms that should have gone off during ten days of unusual volume. The answer depends on evidence of what the company’s access allowed and which limits the register actually enforced, not just on logs showing the queries ran. We saw a similar shape in the Revolut case, where a request from a genuine government email domain was enough to release customer files.

Conclusion: The Access Was Legitimate. The Use Was Not.

The Denmark CPR breach shows why authorization cannot stop at deciding which organization is allowed through the door. The attackers did not need to compromise the national register directly. They operated through a private company’s lawful ability to query it and used that access at a scale the legitimate business relationship should never have required.

Over roughly ten days, automated lookups reached about 8.8 million registered people, close to four in five entries in the CPR system. Each individual request could arrive through an approved access path while the aggregate behavior was clearly outside its intended purpose. That is the central control failure: authentication established who was allowed to query the system, but the surrounding safeguards did not stop that permission from becoming mass enumeration.

The exposed CPR numbers also illustrate why permanent identifiers must not be treated as authenticators. A CPR number identifies a person. It does not prove that the person presenting it is that individual. Once combined with names and addresses at this scale, however, the dataset becomes useful for impersonation, profiling, fraud preparation, and more convincing social engineering.

Why This Threat Matters

  • Legitimate access became the attack path. The register did not need to be directly breached for its data to be extracted.
  • Authorized does not mean unlimited. A company entitled to individual lookups should not automatically inherit the practical ability to enumerate most of the register.
  • Volume is itself a security signal. Millions of automated requests over ten days should be evaluated differently from ordinary business use.
  • Permanent identifiers have long-term value. CPR numbers cannot be treated like passwords that lose usefulness after a reset.
  • Detection came after the access had already scaled. Logs can reconstruct the lookups, but they do not replace limits that should have stopped excessive access as it happened.

Where Defensive Control Must Operate

The strongest control is not another login check. Access must be limited by purpose, expected volume, rate, dataset scope, and the business relationship that justified it in the first place.

Xcitium ITDR adds a critical identity-side layer by exposing when legitimate access begins behaving illegitimately, including abnormal session activity, excessive access patterns, unexpected privilege use, and behavior that no longer matches the identity or organization normally using that access.

Put Limits Behind the Permission

Organizations granting third parties access to high-value registries should assume that a valid account or connection may eventually be misused. Define what normal access looks like, enforce quantitative and contextual limits, alert on enumeration behavior early, and require stronger approval when activity moves beyond the purpose for which access was granted. Authorization should define not only who may enter, but how much they are allowed to reach once they are inside.

Like what you see? Share with a friend.

Move Away From Detection With Patented Threat Prevention Built For Today's Challenges.

No one can stop zero-day malware from entering your network, but Xcitium can prevent if from causing any damage. Zero infection. Zero damage.

Book a Demo