Denmark's CPR population register: unauthorised parties abused one private company's lawful lookup access for about ten days and obtained names, addresses and CPR numbers of 8.8 million people
Denmark's CPR administration noticed irregular behaviour in the register on the evening of Friday 2026-10-02, learned over the weekend that unauthorised parties had obtained names, addresses and CPR numbers of about 8.8 million registered persons, and says the access worked by misusing a Danish private company's lawful right to search the register, within the scope of data that private companies may access (translated from Danish) (Danish Ministry of Research, Education and Digitalisation, 2026-10-05). The register holds about 11 million records, covering living, deceased and emigrated persons, and the ministry says the unauthorised access does not cover the names and addresses of people registered with name-and-address protection; CPR stopped the company's access, reported the incident to the Danish data protection authority, and the police are investigating, with no statement yet on who is behind it (Danish Ministry of Research, Education and Digitalisation, 2026-10-05). Under section 38 of the CPR Act a private company with a legitimate interest may receive information on a larger delimited group of persons that it has identified individually in advance, by CPR number, date of birth and name, or by name and address (Danish Ministry of Research, Education and Digitalisation, 2026-10-05).
The digitalisation minister told Ritzau the access lasted about ten days in September and ran through a smaller Danish company, that an employee of the CPR administration spotted the unusual activity on 2 October, and that red lights should have lit when it went on for so long; she declined to say whether the investigation sees criminal intent at the company (Faglig Senior (Ritzau), 2026-10-05). Datatilsynet, the Danish data protection authority, says the register's notification describes a very large number of automated lookups made to identify valid CPR numbers (translated from Danish) (Datatilsynet, 2026-10-05). No source names the company or says how the access was taken over.
By abusing a Danish company's lawful access to search for information in the CPR system, unauthorised parties have obtained names, addresses, CPR numbers and more on about 8.8 million registered citizens in the CPR system. (translated from Danish)
It is clear to me that the security measures around this company's access to CPR have not been good enough. (translated from Danish)
The notification states that a very large number of automated lookups were made against the CPR system in order to identify valid CPR numbers. (translated from Danish)
It was an expensive invoice that hinted a breach had happened, not systematic alarms. (translated from Danish)
Datatilsynet said on 2026-10-05 that it received the register's notification on Sunday 2026-10-04 and that the notification describes a very large number of automated lookups against the CPR system to identify valid CPR numbers (translated from Danish) (Datatilsynet, 2026-10-05).
At the press briefing of 2026-10-06, DR reports, the authorities said an expensive invoice, not systematic alarms, hinted that a breach had happened, that police have been to a smaller company in person to collect traces, and that foreign police have been contacted in case foreign actors are behind it; the director of the agency for societal security (Styrelsen for Samfundssikkerhed) said the CPR number can no longer be used to authenticate a person (translated from Danish) (DR Nyheder, 2026-10-06). A head of centre at the national police unit NSK said police are looking at whether an algorithm was used, as a hypothesis, because so many lookups were made in a short time, and could not say more (DR Nyheder, 2026-10-06). The authorities did not say who is behind the breach, how it happened or whose access was misused (DR Nyheder, 2026-10-06).