Threat Advisory

Denmark's Central Person Register Breach: 8.8 Million Records Exposed via Abused Third-Party Access

TLT
Threat Landscape Team
2026-10-067 min read

On 5 October 2026, Denmark's Ministry of Research, Education and Digitalisation disclosed a serious security incident in the Central Person Register (CPR). Unauthorized parties abused the legitimate lookup access of a smaller private Danish company and pulled names, addresses, CPR numbers, and related data on roughly 8.8 million registered persons. The access ran for about ten days in September and only surfaced on the evening of 2 October.

Incident at a Glance

Disclosed5 October 2026
RegisterCentral Person Register (CPR), Denmark
Records exposed~8.8 million registered persons
VectorAbused legitimate third-party lookup access
Access window~10 days in September 2026
DetectionIrregular activity noticed 2 October
StatusAccess revoked; Datatilsynet and police investigating

The CPR holds records on about 11 million people: current residents (Denmark's population sits just over six million), people who have emigrated, and the deceased. Individuals with registered name-and-address protection stayed outside the exposed set, according to the ministry's review so far. The company's access has been cut off. The case is with Datatilsynet and the police. Minister Christina Egelund has briefed the Folketing's Business and Digitalisation Committee, ordered a full security review of the CPR system, and said the controls around that company's access "have not been good enough."


What Was Exposed, and Why It Matters

A CPR number is Denmark's lifelong civil registration identifier, usually a date of birth plus a four-digit sequence. It links a person to healthcare, tax, banking, MitID flows, and most contact with public authorities. Private companies can only query a narrower slice of the register than the state itself holds, yet names, addresses, and CPR numbers are already enough to fuel fraud.

A CPR number alone will not complete actions that require MitID. The immediate risk is social engineering. A caller, text, or email that already knows your name, address, and CPR number sounds far more credible. The ministry has told people never to hand over passwords, one-time codes, or other secrets on unsolicited contact, even when the other side recites those details correctly. The national digital-security hotline is running longer hours, and advice is up at sikkerdigital.dk.


How the Access Worked

The attackers stayed inside an authorized channel. Under section 38 of the CPR Act, private companies with a legitimate interest can receive data on people they have already identified, by CPR number or by name plus date of birth or address. For about ten days the unauthorized parties used that route, running what Datatilsynet has described as a very large volume of automated searches aimed at confirming valid CPR numbers.

An employee in the CPR administration noticed irregular activity on Friday 2 October. The picture sharpened over the weekend, Datatilsynet was notified on Sunday, and the public statement came on Monday. The company has not been named. No one has been attributed; the investigation is still early.


Threat-Landscape Implications

The case shows what happens when a trusted lookup integration into a national identity store is weakly watched:

  • Blast radius. One supplier session, used inside the legal query limits, reached most of the register. Every external integration into a centralized population database widens the exposure.
  • Detection lag. Ten days of bulk querying passed until someone noticed odd behavior by hand. Volume, speed, and query-pattern baselines on privileged lookup interfaces needed to be tighter.
  • Fraud enablement. The data set is ready-made for vishing, smishing, and pretexting against Danish residents and against institutions that still treat knowledge of a CPR number as a weak check. Fraud attempts that cite correct personal details are likely to rise in the coming weeks.
  • Scale. Observers have called this the largest breach against the CPR. A 2015 incident involved unencrypted CDs with data on more than five million people sent by mistake to a visa center, with no evidence they were copied. This time the extraction was active and automated through a live integration.

A Second Danish Incident the Same Week

The same week, the Technical University of Denmark (DTU) disclosed a separate intrusion that may have exposed data on up to 200,000 current and former users, CPR numbers included in some cases. Public reporting has not linked the two. Together they show how often Danish personal identifiers sit behind accounts that can be misused.


What Defenders Should Take From It

If you consume CPR data, or you run a similar bulk-lookup interface:

  • Treat every external lookup integration as a privileged channel. Require strong authentication, short-lived credentials, IP allow-listing, and per-client rate and volume limits that alarm well below the scale seen here.
  • Log and baseline query patterns: fields requested, hit rates, time of day, sequential versus scattered identifiers. Automated enumeration of valid identifiers should trigger before it runs for days.
  • Assume CPR numbers and addresses for Danish data subjects in your systems are now more widely known. Tighten help-desk and customer checks that rely on knowing those values, and brief staff on pretexting.
  • Map where national identifiers flow to vendors. This was a supply-chain exposure even though the company was a customer of the register.

What Happens Next

Egelund has said steps are already underway to stop a repeat, and she has left open harder questions, including whether affected numbers should be reissued. That would be operationally heavy given how deeply the identifier is wired into daily life. For now the official line is investigation, a system-wide security review, and public caution against fraud that uses the leaked details.

The episode will be studied for a familiar failure: legitimate access, thin controls on how it was used, and slow detection against a target whose compromise touches almost an entire population register.


Stay ahead of supply-chain and identity exposures with the Threat Landscape Platform — structured STIX intelligence, IoC feeds, and darknet monitoring. Start with a free account, no credit card required, or go Professional from $49/month.

Ready to Transform Your Threat Intelligence?

See how Threat Landscape can reduce alert fatigue and improve your security operations