Denmark CPR Data Breach: 8.8 Million Records

The Denmark CPR data breach exposed the names, addresses and personal ID numbers of about 8.8 million people, roughly four in five records in the country’s Central Person Register. Unauthorized parties reached it through a smaller company’s lawful lookup access, ran more than 14 million queries over about ten days in September, and were noticed only when the register’s administration sent the company its invoice.
What Happened
The Denmark CPR data breach became public on October 5, 2026, when the country’s digitalization ministry announced it. The register’s administration saw irregular activity on the evening of Friday, October 2, worked out the scale over the weekend, and the Danish Data Protection Agency (Datatilsynet) published its own notice on October 5. The exposed data is names, addresses and CPR numbers, the ten-digit ID used for taxes, healthcare and banking. It covers living residents, people who moved abroad and the deceased: 8.8 million of about 11 million records. People with name and address protection are excluded from the name and address data; whether their CPR numbers were reached is not stated.
Private companies with a legitimate interest may look up people they already deal with, and each lookup is billed. According to officials quoted by TV 2 via The Next Web, the company’s account made well over 14 million lookup attempts, of which 8.8 million returned a record. Datatilsynet’s notice describes a very large number of automated lookups made to identify valid CPR numbers. The ministry says the access stayed within the data categories private companies may retrieve. The company’s access has been cut off, police are investigating and no suspect or company has been named. Still open, per The Hacker News: how the unauthorized parties got the company’s access, and whether they kept or used the data. Digitalization minister Christina Egelund said it is clear there is a flaw in the CPR system’s security.
Why It Matters
Nothing here needed an exploit. A valid account, a purpose-limited right and no ceiling on volume were enough. The access terms allow a company to retrieve data on people it has already identified, such as customers or employees, yet one smaller company’s account reached about 80% of the register in ten days. The control that finally worked was the billing run, a finance process rather than a detection. Datatilsynet is now examining what happened, how it was possible and who is responsible for the processing.
The second lesson is about identity. Danish authorities and the Council for Digital Security advise against treating a CPR number on its own as proof of identity and recommend stronger checks such as MitID, a passport or a driving licence. The ministry warns about convincing phishing messages and calls that use names, addresses and CPR numbers. Assessment: German organizations run the same model, with partner APIs, bulk-lookup accounts at registries and credit agencies, and verification built on static data such as date of birth and address. The Danish pattern transfers directly. We covered a related third-party exposure in the GUTcert breach, where customers were exposed through a trusted certifier rather than through their own systems.
What You Should Do Now
- List every external account that can query your personal-data stores in bulk (partner APIs, service accounts, lookup portals), and every such account your organization holds at registries or data providers. Write down the purpose of each.
- Set a volume ceiling per account that matches the expected business volume, and alert on deviation within hours. A monthly invoice or report is not detection.
- Alert on enumeration patterns: dense or sequential identifier lookups and an unusual ratio of hits to misses. Here that ratio was roughly 8.8 million records from more than 14 million attempts.
- Stop accepting a static identifier or knowledge-based data (ID number, date of birth, address) as the only proof of identity. Add a second factor that cannot be derived from registry data.
- If you have Danish customers, employees or partners, brief helpdesk and finance staff on phishing calls and payment-change requests that quote a name, address and CPR number. Danish authorities point affected people to sikkerdigital.dk and the Cyberhotline (+45 33 37 00 37). For notification duties and liability questions, involve your DPO and counsel.
DIESEC Perspective
Access that is legitimate on paper is the hardest to monitor. Contracts and access terms define who may query what, and rarely how much. Organizations that attach a volume ceiling and an anomaly alert to every bulk-lookup right turn a ten-day leak into an alarm on day one.
Not sure whether your partner and service accounts have volume limits and anomaly alerts? Contact DIESEC for a rapid third-party access and lookup-abuse review.
Sources: Help Net Security | The Hacker News | The Next Web | BleepingComputer
Published: 2026-10-09 | Category: Compliance & Governance | ~5 min read

