CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Denmark CPR register third-party access abuse (September 2026)

incident · incident:denmark-cpr-register-third-party-access-2026-10 single-source-victim

Danish authorities disclosed on 2026-10-05 that unauthorised parties abused a private Danish company's lawful search access to the Central Person Register (CPR) for about ten days in September and obtained names, addresses and CPR numbers of about 8.8 million registered persons; the company, the method and the actor are not public (Danish Ministry of Research, Education and Digitalisation, 2026-10-05).

Aliases: Denmark CPR breach, CPR leak

Coverage
1
first 2026-10-06 → last 2026-10-06
Latest activity
2026-10-06
A Danish company's legitimate register access, abused, exposed 8.8 million people's names, addresses and CPR…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: europe
Sources cited
2
2 hosts

Defender insights

What each entry about Denmark CPR register third-party access abuse (September 2026) tells a defender to do, newest first.

2026-10-06NOTABLEA Danish company's legitimate register access, abused, exposed 8.8 million people's names, addresses and CPR numbers

Exposure · detection

Story timeline

  1. 2026-10-06Denmark's CPR population register: unauthorised parties abused one private company's lawful lookup access for about ten days and obtained names, addresses and CPR numbers of 8.8 million people
    active-threatsA Danish company's legitimate register access, abused, exposed 8.8 million people's names, addresses and CPR numbers

Hunting pivots

ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessTrusted Relationship
  • CollectionData from Information Repositories

Initial Access TA0001

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-10-06/denmark-cpr-population-register-third-party-access-breach · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-10-06/denmark-cpr-population-register-third-party-access-breach · ATT&CK page ↗

Entries about Denmark CPR register third-party access abuse (September 2026) (1)

2026-10-06 · view entry permalink →

NOTABLENATOA2

Denmark's CPR population register: unauthorised parties abused one private company's lawful lookup access for about ten days and obtained names, addresses and CPR numbers of 8.8 million people

Denmark's CPR administration noticed irregular behaviour in the register on the evening of Friday 2026-10-02, learned over the weekend that unauthorised parties had obtained names, addresses and CPR numbers of about 8.8 million registered persons, and says the access worked by misusing a Danish private company's lawful right to search the register, within the scope of data that private companies may access (translated from Danish) (Danish Ministry of Research, Education and Digitalisation, 2026-10-05). The register holds about 11 million records, covering living, deceased and emigrated persons, and the ministry says the unauthorised access does not cover the names and addresses of people registered with name-and-address protection; CPR stopped the company's access, reported the incident to the Danish data protection authority, and the police are investigating, with no statement yet on who is behind it (Danish Ministry of Research, Education and Digitalisation, 2026-10-05). Under section 38 of the CPR Act a private company with a legitimate interest may receive information on a larger delimited group of persons that it has identified individually in advance, by CPR number, date of birth and name, or by name and address (Danish Ministry of Research, Education and Digitalisation, 2026-10-05).

The digitalisation minister told Ritzau the access lasted about ten days in September and ran through a smaller Danish company, that an employee of the CPR administration spotted the unusual activity on 2 October, and that red lights should have lit when it went on for so long; she declined to say whether the investigation sees criminal intent at the company (Faglig Senior (Ritzau), 2026-10-05). No source names the company, says how the access was taken over, or says how many queries were made.

By abusing a Danish company's lawful access to search for information in the CPR system, unauthorised parties have obtained names, addresses, CPR numbers and more on about 8.8 million registered citizens in the CPR system. (translated from Danish)

Danish Ministry of Research, Education and Digitalisation 2026-10-05

It is clear to me that the security measures around this company's access to CPR have not been good enough. (translated from Danish)

Faglig Senior (Ritzau) 2026-10-05
incident06 Oct 04:57Zsingle-source · victim disclosureOpen finding →

explore in graph

Where this entity is cited

  • Threats1

Source distribution

  • fagligsenior.dk1 (50%)
  • ufm.dk1 (50%)