2026-10-06NOTABLEA Danish company's legitimate register access, abused, exposed 8.8 million people's names, addresses and CPR numbers
Denmark CPR register third-party access abuse (September 2026)
incident · incident:denmark-cpr-register-third-party-access-2026-10 single-source-victim
Danish authorities disclosed on 2026-10-05 that unauthorised parties abused a private Danish company's lawful search access to the Central Person Register (CPR) for about ten days in September and obtained names, addresses and CPR numbers of about 8.8 million registered persons; the company, the method and the actor are not public (Danish Ministry of Research, Education and Digitalisation, 2026-10-05).
Aliases: Denmark CPR breach, CPR leak
Coverage
1
first 2026-10-06 → last 2026-10-06
Latest activity
2026-10-06
A Danish company's legitimate register access, abused, exposed 8.8 million people's names, addresses and CPR…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: europe
Sources cited
2
2 hosts
Defender insights
What each entry about Denmark CPR register third-party access abuse (September 2026) tells a defender to do, newest first.
Exposure · detection
Story timeline
Hunting pivots
Tags
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessTrusted Relationship
- CollectionData from Information Repositories
Initial Access TA0001
T1199Trusted Relationship×1
Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.
Evidence: 2026-10-06/denmark-cpr-population-register-third-party-access-breach · ATT&CK page ↗
Collection TA0009
T1213Data from Information Repositories×1
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
Evidence: 2026-10-06/denmark-cpr-population-register-third-party-access-breach · ATT&CK page ↗
Entries about Denmark CPR register third-party access abuse (September 2026) (1)
Where this entity is cited
Source distribution
- fagligsenior.dk1 (50%)
- ufm.dk1 (50%)
All cited sources (2)
- fagligsenior.dkFaglig Senior (Ritzau)https://fagligsenior.dk/2026/10/05/cpr-laek-i-ti-dage-minister-erkender-svigt-i-sikkerheden/
- ufm.dkDanish Ministry of Research, Education and Digitalisationhttps://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/