HomeSecurityCPR Register Denmark: Data leak of 8.8 million people

CPR Register Denmark: Data leak of 8.8 million people

CPR Register was at the center of one of the largest data breaches in the country’s history, when the Ministry of Digital Governance announced on October 5, 2026 , that unauthorized individuals had gained access to the names, addresses and identification numbers of approximately 8.8 million people. The breach did not occur through a direct hack of the database, but through a private company’s legal access to the register. The case has already been referred to the data protection authority Datatilsynet , and the police are investigating.

CPR Register Denmark data breach 8.8 million people

The Central Person Register (CPR) has been in operation since 1968 and records every person who lives or has lived in Denmark. The register contains a total of about 11 million records, meaning the breach affects about 80% of all records. This number exceeds the population of Denmark — which stood at just under 6 million inhabitants in early 2025 — because the register includes living residents, deceased people, immigrants and people who have moved abroad. Minister for Digital Governance Christina Egelund called the incident serious and admitted that the security surrounding the company’s access was inadequate.

See also: People's Cyber ​​Army teams up with other groups for DDoS attacks in Denmark

According to the information that has been made public, the suspicious activity lasted for approximately 10 days in September 2026.A registry administrator detected the unusual activity on Friday, October 2, and over the weekend, authorities determined the exact number of affected records. The company's access was blocked immediately after the breach was discovered and the case was reported to Datatilsynet.

How the CPR Register breach happened

The crucial question that remains unanswered is how the unauthorized users gained access to the company’s systems. The available evidence suggests that a large number of automated searches were carried out on the registry, with the aim of identifying valid CPR. This pattern suggests an enumeration or brute-force — that is, systematically testing identification numbers to identify valid ones and then retrieving the associated data. The fact that the breach lasted 10 days without being immediately detected raises serious questions about the adequacy of the anomaly detection mechanisms and search ratelimitingthat were implemented.

CPR Register - SecNews.gr

This scenario falls into a broader category of attacks that leverage legitimate third-party to bypass traditional defenses. Rather than directly attacking the government system, the attackers targeted a small private company with legitimate access to the CPR Register. This approach — known as a third-party supply chain attack — is particularly effective because it exploits weak links in the chain of trust. A government agency may maintain strong defenses in its own infrastructure, while an affiliated company may have much weaker identity, endpoint, or application security.

Possible scenarios for how access was gained include credential theft,a breach of a company's endpoint or application, an exposed API key, an insiderthreat, or exploiting weaknesses in the company's interface with the registry. None of these have been publicly confirmed.

See also: Cumberland County Register of Deeds online search down due to ransomware

Risks from the CPR Register data leak and what citizens should do

Exposing names, addresses and CPR poses serious risks to victims. The stolen data can be used for sophisticated phishing and social engineering, where attackers appear to know personal details in order to gain trust. In addition, the identification numbers can be used for identity theft, credit card fraud, false loan applications and bypassing identity verification processes. The ministry stressed that the CPR number should never be used as the sole proof of identity.

Article image: Attackers use passkey-themed scams to hijack Microsoft 365 accounts

The authorities in Denmark have issued specific instructions for citizens. They recommend that they be particularly wary of unexpected messages, calls or emails in which the sender uses personal information. Also, they should not click on links from unknown sources, and never share MitID, one-time codes, passwords or card details. Finally, it is recommended to activate a credit warning via the borger.dk — a mark in the CPR that alerts companies to be particularly careful before granting loans or credit in the holder's name. This mark is available to everyone over 15 years of age.

It is worth noting that the breach did not affect people who had activated name and address protection — in these cases, the registry does not disclose this information to private companies. However, the official announcements do not clarify whether the CPR numbers of these people were also protected. It has also not been announced whether the 8.8 million victims will be individually notified or whether their CPR numbers will be replaced.

From a technical perspective, the incident highlights critical weaknesses in access governance . Simple authentication is not enough — a legitimately authenticated company account can be misused if credentials are stolen. Authorization must be granular: access must be restricted by purpose, data fields, demographic segment, search volume, and time. Behavioral monitoring is essential — a company that typically performs few searches should immediately trigger alerts if its account suddenly performs hundreds of thousands or millions of searches. Audit logs must be actively analyzed, not just stored.

See also: Oracle PeopleSoft: Attacks bypass WAFs and deploy web shells

Article image: ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel

This incident is a stark reminder that any organization with privileged access to government records is a potential entry point for attackers. Authorities should require phishing-resistant multifactor authentication — preferably with FIDO2 — for every third-party account, enforce strict search rate limits and daily quotas, and conduct regular red team to identify weaknesses in third-party interfaces. According to The Hacker News, authorities have not yet revealed the identity of the attackers, how access was gained, or whether the data has already been used. The case remains under investigation, and a full report from the Datatilsynet and police authorities is awaited.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS