Denmark's CPR population register breach exposes data on 8.8 million people
Denmark disclosed that unidentified actors misused a private company's legitimate access to the national Central Person Register (CPR) to extract the names, addresses and personal identification numbers of about 8.8 million people.
- Victim
- Denmark Central Person Register (CPR)
- records
- 8.8M
- users
- 8.8M
On 5 October 2026, Denmark โ through its government's digitalisation authority โ disclosed a major security incident affecting the Central Person Register (CPR), the national database that assigns every resident a unique 10-digit identification number used across public services, banking and healthcare. Unidentified actors misused a private Danish company's legitimate access to the register to extract records on roughly 8.8 million people, far more than the company's authorisation under Danish data rules should have allowed.
The exposed information includes names, addresses and CPR numbers, along with other data held in the register. Because the CPR holds records on living residents, people who have emigrated and the deceased, the 8.8 million figure exceeds Denmark's resident population of about six million. People who had registered for name and address protection were not exposed in the leak.
Detection and response
Irregular behaviour in the CPR system was first detected on the evening of Friday 2 October 2026, with the unauthorised access traced back to an unspecified point in September. The company involved was blocked from the system while police opened an investigation, and authorities said it was too early to determine who was behind the breach. Digitalisation Minister Christina Egelund called it "a deeply serious incident," ordered a comprehensive security review of the CPR system, and urged residents to watch for suspicious communications.
Why it matters
The breach is one of the largest ever to hit Denmark and underlines a recurring systemic risk: a well-defended government register can still be drained wholesale through a trusted third party's credentials. CPR numbers are deeply embedded in Danish identity verification, so their mass exposure heightens the risk of identity fraud and targeted phishing for nearly the entire population, even though the leaked fields stop short of financial or health data.
Timeline
Unauthorised searches of the Central Person Register begin, far exceeding the scope of the company's legitimate authorisation.
Danish authorities detect irregular activity in the CPR system on the evening of Friday 2 October and block the company's access.
The government publicly discloses the breach; Digitalisation Minister Christina Egelund orders a comprehensive security review of the CPR system.
Sources
- insurancejournal.comhttps://www.insurancejournal.com/news/international/2026/10/05/887972.htm
- irishtimes.comhttps://www.irishtimes.com/world/europe/2026/10/05/denmark-breach-exposes-personal-data-of-88-million-people/
- cphpost.dkhttps://cphpost.dk/2026-10-05/life-in-denmark/cpr-data-breach-exposes-personal-details-of-8-8-million-people-in-denmark/
- itsecurityguru.orghttps://www.itsecurityguru.org/2026/10/05/denmarks-cpr-breach-exposes-8-8-million-people-as-experts-warn-over-trusted-third-party-access/