Denmark CPR Breach: 8.8M Records Pulled Through One Vendor's Legitimate Lookup Access
🛡️ Security •

Denmark CPR Breach: 8.8M Records Pulled Through One Vendor's Legitimate Lookup Access

Attackers misused a small Danish company's lawful CPR lookup access for about ten days in September, extracting names, addresses and ID numbers for 8.8 million people. No CVE, no exploit.

data breachdenmarkcprthird-party accessenumeration

What Happened

On Monday 5 October 2026 Denmark's Ministry of Research, Education and Digitalisation confirmed the largest breach in the history of the country's Central Person Register (CPR). Unauthorised parties obtained the names, addresses and CPR numbers of approximately 8.8 million registered persons. The register holds roughly 11 million records in total, covering current residents, people who have emigrated and people who have died, so the exposed set is most of the register and well beyond Denmark's population of just over 6 million.

The intrusion was not a break-in to government servers. According to the ministry's statement, the attackers misused a private Danish company's lawful access to search the CPR system. The queries ran inside the parameters that private businesses are normally allowed to use; it was the volume and the purpose that were illegitimate. The Record reported that a very large number of automated searches were used to identify valid CPR numbers. Danish broadcaster TV 2 described the firm as a smaller Danish company and said the access was abused for about ten days.

The timeline is short. The CPR administration noticed irregular behaviour in the system on the evening of Friday 2 October. Over the weekend its review established that the irregularities dated to September and that they amounted to a mass extraction. The company's access was blocked, the Danish Data Protection Agency (Datatilsynet) was notified on Sunday, and the police opened an investigation. The public announcement followed on Monday morning, with a parliamentary briefing scheduled for the same afternoon.

Minister Christina Egelund called it "a deeply serious incident" and, in remarks carried by TV 2, said the security measures around the company's CPR access "were clearly not adequate enough". She has ordered a broad security review of the CPR system.

Who Is Affected

Almost everyone with a Danish CPR number, living or dead, resident or abroad. The one group excluded is people registered with name and address protection. The ministry's statement says the unauthorised access did not include names or addresses for those individuals.

A CPR number is a ten-digit identifier that begins with the holder's date of birth and is designed to last for life. It is used across healthcare, banking and government services. That makes the exposed triple of name, address and CPR number a complete identity kit in a country where the number was never meant to function as a secret but is routinely treated as one by call centres, help desks and web forms. Professor Jens Myrup Pedersen of Aarhus University told DR that the combination of CPR number and address is what makes this incident worse than the 2015 case, in which two unencrypted CDs holding more than 5 million CPR records were mistakenly sent to a visa application centre and were never shown to have been copied.

For IT and security teams outside Denmark, the relevance is structural rather than geographic. Any organisation that grants partners query access to a large identity dataset, whether a national registry, a customer master, an HR system or a credit bureau feed, has the same exposure. The data left Denmark through a trusted front door that had been built, authorised and audited for exactly that kind of lookup.

Technical Analysis

Three features of the incident deserve attention from anyone who runs or consumes a lookup service.

First, the attack surfaceAttack Surface🛡️The sum of all points where an unauthorized user could attempt to enter or extract data from a system: exposed services, interfaces, accounts, and integrations. Reducing attack surface means removing reachability, not just patching. was an authorised integration, not a vulnerabilityVulnerability🛡️A weakness in software, hardware, or processes that can be exploited by attackers to gain unauthorized access or cause harm.. There is no CVE and no patch. The company held a legitimate connection to the CPR search functions under the arrangements that let Danish businesses with a lawful interest verify registry data. Whether the attackers compromised the company's credentials, its systems or an insider has not been disclosed. From the registry's point of view every request arrived from a known client and asked a permitted question. Why Third-Party Lookup Access Is an Enumeration Oracle Waiting to Be Abused covers why that pattern is so hard to defend after the fact.

Second, the identifier space was small enough to walk. The Record's account that the attackers used a very large number of automated searches to find valid CPR numbers fits the structure of the number itself: six digits of birth date followed by four more. A client that is allowed to ask "does this number exist, and who is it?" can be driven through the candidate space by a script, and a single tenant that is permitted ten thousand lookups a day will quietly become one that performs millions if nothing stops it. Each successful hit returns name and address. That is enumeration, and the register answered it for roughly ten days.

Third, detection happened late and from the registry side. The CPR administration spotted irregular behaviour on 2 October and, within a weekend, reconstructed activity dating back into September. That is a credible forensic response, but it means the volume anomaly was visible in the logs the whole time and nothing alerted on it as it happened. Pedersen's recommendations to DR are the obvious ones: restrict companies to the data they actually need, alarm on unusual lookup patterns, and tighten vendor security requirements. How to Detect Bulk Enumeration Through a Partner's API Credentials Before It Finishes walks through what that alerting looks like in practice.

A note on what is not known. The company has not been named. The method used to obtain its access has not been described. No actor has been identified, and the police, through National Special Crime Unit deputy inspector Nicklas Fallesen, describe the investigation as being in its early phases. Nothing yet indicates where the data went or whether it has been sold.

Immediate Actions

For Danish organisations and anyone who serves Danish customers:

  • Stop treating a CPR number as proof of identity. Knowledge of a CPR number, name and address should now be assumed to be available to criminals for most of the population. The government's own advice is that callers who know your personal details are not thereby legitimate, and that passwords and one-time codes must never be shared by phone, email or text. Why a National ID Number Can Never Be a Secret, and What to Authenticate With Instead explains how to restructure verification flows around that reality.
  • Route identity assurance through MitID. TV 2 reports the official guidance is to use MitID as the primary means of identification going forward and that no new CPR numbers will be issued.
  • Expect a wave of targeted phishingPhishing🛡️A social engineering attack using fake emails or websites to steal login credentials or personal info. and vishingVishing🛡️Voice phishing—a social engineering attack conducted via phone calls where attackers impersonate trusted entities to extract sensitive information or payments.. Attackers now hold enough accurate detail to impersonate banks, tax authorities and municipalities convincingly. Brief help desks and customer-facing staff that reciting a correct CPR number is no longer a signal of anything.
  • Point affected individuals to the official channels. Citizens can register a credit warning via borger.dk, and the national cyber hotline on +45 33 37 00 37 is operating extended hours from 08:00 to midnight.

For anyone who operates a lookup service or grants partners query access to personal data:

  • Pull the per-client query logs for the last 90 days and look for sustained volume well above each tenant's historical baseline. The CPR case shows that a ten-day anomaly was large enough to extract most of a national dataset without tripping a real-time alarm.
  • Confirm that every partner integration has a hard ceiling on requests per hour and per day, enforced server-side, and that responses to non-existent identifiers are indistinguishable in timing and content from responses to protected ones.
  • Review what each integration can retrieve. A verification use case needs a yes or no, not a name and address.

Long-Term Outlook

Denmark is now confronting a problem that the United States has lived with since the Equifax breach of 2017: a lifetime identifier, held by essentially everyone, has leaked for essentially everyone. Anne Dorte Bach, deputy chair of the Council for Digital Security, told TV 2 that the CPR system itself is outdated and should be abandoned. That is a multi-year policy debate. The near-term engineering consequence is simpler. Every Danish service that still uses CPR knowledge as an authentication factor has to assume that factor is now public and move the weight onto MitID, device binding and transaction confirmation.

The ordered security review will almost certainly scrutinise how private companies obtain and retain lookup access, what rate and volume controls apply per client, and why a mass extraction was detectable only in retrospect. Those are the same questions worth asking of any system you operate that answers identity queries for third parties. The attacker did not need an exploitExploit🛡️Code or technique that takes advantage of a vulnerability to cause unintended behavior, such as gaining unauthorized access.. They needed one trusted integration and ten quiet days.

Sources

  • Danish Ministry of Research, Education and Digitalisation, press release "Omfattende uautoriseret adgang til borgeres CPR-oplysninger", 5 October 2026: https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/
  • CPR-administrationen, notice of the same title, 5 October 2026: https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger
  • The Record (Alexander Martin), "Data breach at Denmark's national population register exposes 8.8 million people", 5 October 2026: https://therecord.media/denmark-breach-register-cyberattack
  • TV 2 Nyheder live coverage, 5 October 2026: https://nyheder.tv2.dk/live/samfund/2026-10-05-cpr-numre-kompromitteret/skaffede-oplysninger-gennem-dansk-virksomhed
  • DR, "Professor: Det største brud nogensinde mod det danske CPR-register", 5 October 2026: https://dr.dk/nyheder/indland/professor-det-stoerste-brud-nogensinde-mod-det-danske-cpr-register
  • SecurityOnline, "Denmark CPR Data Breach Exposes CPR Numbers of 8.8 Million People", 5 October 2026: https://securityonline.info/denmark-cpr-data-breach/
  • GBHackers, "Denmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records", 5 October 2026: https://gbhackers.com/denmark-confirms-major-security-incident/