The news
The Denmark CPR breach, disclosed on October 5, gave unauthorized parties the names, addresses and national ID numbers of about 8.8 million people listed in the Central Person Register (CPR), Danish authorities said. The intruders abused a Danish company's legitimate access to search the register.
According to the CPR office and the Ministry of Research, Education and Digitalization, the unauthorized access took place in September. CPR administrators spotted irregular activity on the evening of Friday, October 2, and confirmed over the weekend that citizen data had been accessed. The ministry said unauthorized parties used the company's lawful search access, within the kind of lookups normally available to private businesses; The Record reported the searches were automated and aimed at identifying valid CPR numbers.
The 8.8 million figure covers people registered in the CPR system, including people who have died or moved abroad, out of about 11 million registrations, the ministry said. People who had registered for name and address protection were not affected, according to the CPR office. BleepingComputer reported that dates of birth and marital status were also exposed; the official notices list names, addresses and CPR numbers among the data.
The CPR office suspended the company's access, reported the incident to the Danish Data Protection Agency and said police are investigating with other agencies. Minister Christina Egelund called it an extremely serious incident and said she had informed the Danish parliament's Business and Digitalization Committee. Authorities have not named the company or the people behind the access.
CPR numbers are 10-digit identifiers that begin with a person's date of birth and are used across Danish healthcare, banking and government services, The Record noted, describing them as roughly comparable to US Social Security numbers. It called the incident the most significant for the CPR system since 2015, when two unencrypted CDs with CPR data on more than 5 million people were mistakenly delivered to the wrong recipient. TechCrunch reported the breach is thought to be the biggest in Denmark's history.
The ministry advised people to consult the government's sikkerdigital.dk guidance and never share passwords by phone, email or similar channels, even when a request seems to come from someone familiar. It also expanded the hours of its cyber hotline to 8 a.m. to midnight.
The numbers
- People whose CPR data was obtained
- About 8.8 million
- Total registrations in the CPR system
- About 11 million
- When the unauthorized access took place
- September 2026
- Irregular activity detected
- October 2, 2026
- Previous major CPR incident (per The Record)
- 2015, 5 million+ people
Why CEOs should care
For banks, fintechs, insurers and employers that onboard Danish customers or staff, the main risk is identity verification. A CPR number, which also reveals a birth date, paired with a name and address is the kind of data used in Know Your Customer (KYC) checks. If any step in your onboarding, password reset or call-center script treats those details as proof of identity, assume an impostor may now hold them, and require something only the real person has, such as a code sent to a verified device or a document check.
CISOs should expect phishing and phone scams that use accurate personal details to sound credible, which is why Danish authorities warned people not to share passwords by phone or email. Brief help desks and customer-service teams, and flag unusual address changes, account recovery requests and new-credit applications tied to Danish identities.
Boards and risk officers should note how the data came out: through a business's legitimate search access, according to officials. Any company holding API or search access to government or credit-bureau databases should review who can use those credentials, cap query volumes and alert on bulk or automated lookups. Contracts with data providers should spell out who is responsible when a customer's access is misused.
The bigger picture
The incident follows a pattern US security teams know well: data pulled through an authorized path, such as a partner account, an API or a data-broker lookup, can be harder to spot than a break-in because each query looks routine. In Denmark, the activity ran during September and was spotted on October 2, according to the ministry.
Lifetime identifiers also make such breaches long-lived. The Record noted that CPR numbers are used for life, which raises long-term identity theft concerns; unlike a password, a national ID number is not easily replaced.
What’s next
Watch for the results of the police investigation, whether officials name the company whose access was misused, and the findings of the security review the ministry has started. Businesses with Danish customers should also watch for any sign the data is offered for sale and for guidance from Danish regulators on identity checks.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







