8.8 Million People Affected by Unauthorized Access to Denmark’s CPR Registry

Denmark is investigating a CPR breach that exposed personal data tied to 8.8 million registered people through a private company’s legitimate access.

Written By
Liz Ticong
Liz Ticong
Oct 6, 2026
3 minute read
Unauthorized access to Denmark’s CPR system exposed personal data tied to about 8.8 million registered people.

Unauthorized access to Denmark’s CPR system exposed personal data tied to about 8.8 million registered people. Image generated with ChatGPT.

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Personal data tied to about 8.8 million people was accessed without authorization through Denmark’s Central Person Register, including names, addresses, and CPR numbers.

Officials detected irregular activity on Oct. 2 and traced the searches back through September. Investigators say the activity involved legitimate CPR access belonging to a private Danish company rather than a confirmed direct compromise of the national registry itself.

Authorities have not identified who was behind the access or disclosed what happened to the information collected.

Registry records extend beyond current Danish residents

Names and addresses, along with CPR numbers, were among the information accessed. People registered for name-and-address protection were excluded from that portion of the unauthorized access.

CPR contains records for about 11 million registered people, including current residents as well as people who have moved abroad or died. Affected records therefore are not limited to people currently living in Denmark.

Automated searches ran through legitimate company access

An unnamed private Danish company’s legitimate permission to search CPR was used without authorization. Investigators have not reported a direct compromise of the registry itself.

Denmark’s Data Protection Agency reported a very large number of automated searches intended to identify valid CPR numbers. Investigators have not disclosed how the company’s access was compromised or misused, or what happened to information collected through the searches.

CPR administrators shut down the company’s access after detecting the activity. Police are investigating, and officials have started a wider security review of access to the registry.

Advertisement

CPR exposure changes what affected residents can trust

If your information was among the records accessed, someone knowing your name, address, or CPR number should not be enough to earn your trust. Attackers can work real personal details into phishing messages that appear to come from a bank, government agency, or another organization you already deal with.

Voice phishing can be even more persuasive when a caller already has accurate information. Someone could repeat your address or CPR number to establish credibility before asking for additional details, directing you to a login page, or trying to get you to approve an authentication request. Recent vishing incidents have shown how leaked information can support convincing phone-based scams.

CPR details are identifying information, not proof that someone is who they claim to be. Customer support and account-recovery processes that rely on personal details should use another form of verification, such as an authenticated account session or a separate trusted channel. 

Denmark’s security guidance for the incident gives affected residents several practical steps:

  • Verify unexpected contact through an official app, website, or known phone number rather than trusting the details a caller or message already has.
  • Do not share MitID information, passwords, or payment details in response to unsolicited contact.
  • Treat unexpected authentication requests with caution, especially when someone is pressuring you to approve them.
  • Consider creating a credit warning in CPR to reduce the risk of someone seeking credit in your name.

Authorized access also needs stronger limits behind the scenes. High-volume searches from legitimate accounts should be monitored and stopped when activity falls outside normal use, before one set of permissions can be used to collect data at this scale.

More on data breaches: Over 95,000 customer emails were exposed after a generative AI-assisted program failed to hide recipient addresses in a bulk mailing.

Liz Ticong

Liz Ticong is a staff writer for eWeek and TechRepublic focused on AI, cybersecurity, enterprise software, and data. She has more than 10 years of editorial experience as a technology industry writer, combining reporting, product research, and hands-on software testing in her coverage. Her work has been published on Datamation, Enterprise Networking Planet, and TechnologyAdvice.com. She writes technology news, software reviews, product comparisons, and buyer’s guides for business and IT readers.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.