CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOA2incident

Denmark's CPR population register: unauthorised parties abused one private company's lawful lookup access for about ten days and obtained names, addresses and CPR numbers of 8.8 million people

A Danish company's legitimate register access, abused, exposed 8.8 million people's names, addresses and CPR numbers

Analysis

Denmark's CPR administration noticed irregular behaviour in the register on the evening of Friday 2026-10-02, learned over the weekend that unauthorised parties had obtained names, addresses and CPR numbers of about 8.8 million registered persons, and says the access worked by misusing a Danish private company's lawful right to search the register, within the scope of data that private companies may access (translated from Danish) (Danish Ministry of Research, Education and Digitalisation, 2026-10-05). The register holds about 11 million records, covering living, deceased and emigrated persons, and the ministry says the unauthorised access does not cover the names and addresses of people registered with name-and-address protection; CPR stopped the company's access, reported the incident to the Danish data protection authority, and the police are investigating, with no statement yet on who is behind it (Danish Ministry of Research, Education and Digitalisation, 2026-10-05). Under section 38 of the CPR Act a private company with a legitimate interest may receive information on a larger delimited group of persons that it has identified individually in advance, by CPR number, date of birth and name, or by name and address (Danish Ministry of Research, Education and Digitalisation, 2026-10-05).

The digitalisation minister told Ritzau the access lasted about ten days in September and ran through a smaller Danish company, that an employee of the CPR administration spotted the unusual activity on 2 October, and that red lights should have lit when it went on for so long; she declined to say whether the investigation sees criminal intent at the company (Faglig Senior (Ritzau), 2026-10-05). No source names the company, says how the access was taken over, or says how many queries were made.

Cited evidence

By abusing a Danish company's lawful access to search for information in the CPR system, unauthorised parties have obtained names, addresses, CPR numbers and more on about 8.8 million registered citizens in the CPR system. (translated from Danish)

Danish Ministry of Research, Education and Digitalisation 2026-10-05

It is clear to me that the security measures around this company's access to CPR have not been good enough. (translated from Danish)

Faglig Senior (Ritzau) 2026-10-05

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.