One company's access, 8.8M Danes exposed: inside Denmark's CPR register breach
What happened? On 5 October 2026, Denmark's Ministry of Higher Education, Research and DigitalisationDealroom has a profile for this one. Try Dealroom → disclosed a serious security incident at the Central Person Register (CPR), the country's national civil registration system. Unauthorised individuals obtained names, addresses and CPR numbers of around 8.8 million registered people, including living residents, emigrants and the deceased. People registered with name and address protection were not affected. The register holds records on about 11 million people, against a resident population of roughly 6 million.
How it happened: The attackers did not break into the CPR system directly. They misused a private Danish company's legitimate access to search the register, which private firms with a justified interest can obtain under section 38 of the CPR Act. The CPR administration noticed irregular activity on the evening of 2 October 2026 and established that the searches took place during September 2026. It has blocked the company's access, notified the Danish Data Protection Agency (Datatilsynet), and the police are investigating. The company has not been named, and the authorities say it is too early to say who is behind the breach.
Why it matters: The CPR number is the backbone of Denmark's highly digitised public sector and is used to identify people with government agencies, banks and healthcare providers. Minister Christina Egelund called the incident deeply serious, ordered a thorough security review of the CPR system and urged citizens to be alert to phishing calls and emails that use the leaked details. The case also puts scrutiny on how third-party access to national registers is granted and monitored.
Who works on this problem? Breaches through a trusted partner's valid access are a known blind spot, and several security companies target it. Copenhagen-based Omada sells identity governance software that tracks who has access to which systems and whether they still need it. Silverfort protects identities, including machine and service accounts, and can block suspicious use of valid credentials. Salt Security monitors APIs for abnormal query patterns such as mass lookups. Varonis and Cyera map where sensitive data sits and flag unusual access to it.
Read more: Danish Ministry statement · Bloomberg · The Copenhagen Post · RTL Nieuws