Denmark's CPR Breach: When a Lookup Number Becomes a Skeleton Key to 8.8 Million Identities
Abuse of a small Danish firm's legitimate register access exposed names, addresses and CPR numbers for 8.8 million people, living and dead. The cause and scale of misuse remain unconfirmed.
Updated 6 October 2026. This briefing separates what has been confirmed from what has only been claimed, and will be updated as the facts develop.
Denmark's Central Population Register (CPR) has confirmed that an unauthorised party abused a small private company's legitimate access to the register, exposing names, addresses, CPR numbers and other personal data belonging to around 8.8 million people. The register holds roughly 11 million records in total, including residents, people who have died, and people who have moved abroad, which is why the affected total exceeds Denmark's current population of just under 6 million. An employee at the register's administration noticed unusual activity on 2 October, and the administration established the scale of the exposure over the following weekend. The access itself took place over roughly ten days in September.
Denmark's Data Protection Agency, Datatilsynet, says the activity involved a very large number of automated lookups used to identify valid CPR numbers, which it describes as a form of enumeration or brute-forcing, before related record data was extracted. Digitisation minister Christina Egelund has called this an extremely serious incident, informed parliament's Business and Digitalization Committee, and ordered a full security review of the register. The company's access has been blocked, the breach has been reported to Datatilsynet, and police have opened an investigation. Egelund said it was too early to say whether Denmark would need to issue new CPR numbers to affected citizens.
The ministry has stressed that names and addresses of people registered under Denmark's name-and-address protection scheme were not exposed, and that the breach stayed within the categories of data private companies are legally permitted to receive. It has not explained how one small company's access, meant to cover a defined set of identified customers or employees, came to cover roughly four in five people on the entire register.
What is confirmed, and what is not
- Confirmed: around 8.8 million CPR records were accessed via a private Danish company's legitimate register access, exposing names, addresses, CPR numbers and related data.
- Confirmed: the access ran for about ten days in September 2026 and was discovered on 2 October.
- Confirmed: Datatilsynet describes automated lookups used to enumerate valid CPR numbers, though it has not yet formally assessed the case and calls the retrieved numbers "allegedly" obtained.
- Not confirmed: how the unauthorised party gained access to the company's systems in the first place.
- Not confirmed: who is behind the breach, or whether the data has been retained, sold or used since.
- Not confirmed: whether individual affected people will be notified directly, or whether new CPR numbers will be issued.
The identity angle
This is a case about machine-to-system identity, not just human credentials. The exposure did not come from a phishing attack on individuals, but from abuse of a third-party organisation's standing, legitimate access to a national identity register. That access was meant to be scoped to specific, pre-identified individuals a company already dealt with, such as customers or employees. Somehow it was used, or abused, to reach data on a far larger population. This points to a gap between the access a system technically grants and the access its governance assumes is being used. The CPR number itself, a static, guessable ten-digit identifier, is also central to the problem: it is used across Denmark as a near-universal key for public services, banking and healthcare, despite official guidance that it should never be treated as sole proof of identity. When a single number functions as both an identifier and an implicit authenticator, exposing it at scale creates downstream fraud risk that outlives the original breach.
What to check this week
- Review every third-party or partner integration that holds standing access to sensitive registers or databases, and confirm the access is scoped technically, not just contractually, to the specific records it is meant to cover
- Check whether lookup or query volumes from partner accounts are monitored for anomalies, such as sequential or enumerative patterns, rather than only for failed logins
- Confirm that any identifier used across multiple systems, such as a national ID or CPR-style number, is never treated as a secret or sole proof of identity in your own verification flows
- Test whether your systems would detect a sudden spike in automated lookups against a partner's existing, legitimate access within hours rather than weeks
- Verify that alerting thresholds exist for sustained unusual activity over days, not just single suspicious events, since this access went unnoticed for around ten days
- Review whether affected individuals in similar schemes would be notified directly, and have a communication plan ready that does not rely on phone or email contact, given the current guidance against trusting unsolicited calls referencing personal details
- Check that credit or fraud warning mechanisms equivalent to Denmark's "credit warning" marker are available and well understood by your user base before an incident forces rapid uptake
The takeaway
A legitimate, narrowly intended access grant became a route to nearly every record in a national register, and the full cause is still unknown. The lesson for identity leaders is not just about this one Danish company, but about how little daylight there often is between "access granted" and "access abused" when third-party connections to sensitive systems are not tightly scoped and actively watched.
If you would like a second pair of eyes on your exposure, get in touch.
Sources and further reading
- Denmark's ID register spills more people's details than the country has residents (The Register)
- Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account (The Hacker News)
- Denmark population registry data breach affects 8.8 million people (BleepingComputer)
Source links support the documented product behaviour. Recommendations and labelled examples are editorial guidance.