Skip to main content
The Wire
CyberNews by Zentrya One
Data Breaches

Denmark Says Attackers Accessed CPR Data of 8.8 Million People Through Company Account

Denmark investigates unauthorized access to CPR data linked to about 8.8 million people after attackers abused a private company's legitimate access to the national population register.

Danish authorities are investigating a major security incident involving the country's Central Person Register (CPR) after unauthorized parties accessed personal information associated with approximately 8.8 million registered people.

The attackers did not directly compromise the national register through a disclosed software vulnerability. Instead, they abused the legitimate CPR access available to an unnamed private Danish company to perform a large number of automated lookups.

What Information Was Accessed?

According to Denmark's Ministry of Research, Education and Digitalisation, the accessed information included:

  • Names
  • Addresses
  • CPR personal identification numbers
  • Other information available through the company's permitted level of CPR access

The approximately 8.8 million records include living residents as well as people who have moved abroad and deceased individuals.

Denmark's CPR contains information relating to roughly 11 million registered people, meaning the incident potentially involved records for around four out of every five people contained in the database.

Attackers Abused Legitimate Company Access

Private Danish companies can receive access to certain CPR information when they have a legitimate business requirement and meet applicable legal conditions.

In this incident, unauthorized individuals abused one company's legitimate access.

Denmark's Data Protection Agency, Datatilsynet, said a very large number of automated lookups were performed to identify valid CPR numbers. However, authorities have not yet publicly explained how the attackers obtained control of the company's access.

The attack can currently be summarized as:

Company Has Legitimate CPR Access → Unauthorized Party Obtains/Abuses Access → Automated CPR Lookups → Millions of Records Accessed

There is currently no disclosed CVE or evidence that attackers exploited a vulnerability directly within the CPR platform.

Activity Continued for Around 10 Days

The unauthorized activity reportedly lasted approximately 10 days during September 2026.

The CPR administration detected unusual activity on October 2, after which investigators spent the weekend determining the potential scale of the incident.

The affected company's access has since been terminated, the incident has been reported to Datatilsynet, and Danish police have launched an investigation.

Attackers Have Not Been Identified

Several important questions remain unanswered.

Authorities have not publicly identified:

  • Who conducted the attack
  • How the company's CPR access was compromised
  • Whether an insider was involved
  • Whether the information was retained by the attackers
  • Whether the information has been sold or shared
  • Whether it has already been used for fraud

For this reason, it is more accurate at this stage to describe the information as accessed rather than claim that all 8.8 million records were definitively stolen or leaked.

Identity Fraud and Phishing Are Major Concerns

The combination of names, addresses and CPR numbers could make highly convincing social-engineering attacks possible.

Attackers could potentially use accurate personal details to impersonate banks, government agencies or other trusted organizations.

Danish authorities are therefore advising people to:

  • Be suspicious of unexpected calls, emails and text messages.
  • Avoid clicking links contained in unsolicited messages.
  • Never disclose MitID credentials or verification codes.
  • Never provide passwords or payment-card details.
  • Consider placing a credit warning on their CPR record.

A CPR number alone should not be treated as sufficient proof of someone's identity.

Security Takeaway

The incident highlights the cybersecurity risk created by trusted third-party access to highly sensitive centralized databases.

The CPR system itself did not necessarily need to be directly breached. Compromising or abusing an authorized organization's access could provide attackers with another route to sensitive information.

The incident demonstrates the importance of:

Strong Third-Party Authentication → Least-Privilege Access → Query Rate Limiting → Behavioral Monitoring → Automated Anomaly Detection

Organizations managing sensitive national or customer databases should monitor not only unauthorized login attempts but also unusual behavior from legitimate authenticated accounts, particularly high-volume automated queries.

Danish authorities have already introduced additional measures and ordered a broader security review of the CPR system while the investigation continues.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.