Denmark's CPR Register Breach Took 8.8 Million Records Through a Contractor's Access
Security / news
Denmark's CPR Register Breach Took 8.8 Million Records Through a Contractor's Access
No software flaw was involved. Someone misused a private Danish company's lawful right to query the population register, and the accounts of what leaked differ by outlet.

Unauthorised parties pulled about 8.8 million records from Denmark's Central Population Register (CPR) in September by misusing the lawful search access of a private Danish company, the government said on October 5. The register holds roughly 11 million people, so the copy covers about four in five entries.
No software patch applies here, because officials say no known vulnerability was used. The weakness is the access arrangement itself, and police have not said who is behind it.
What the government has said
The announcement came from the Ministry of Research, Education and Digitalisation. Minister Christina Egelund said, according to The Copenhagen Post: "It is a deeply serious incident, which I have therefore also briefed the Folketing's Business and Digitalisation Committee about."
The Copenhagen Post puts the incident in September and says it was noticed on a Friday evening. Cybersecuritynews dates the unusual activity to October 2 and says investigators confirmed the breach the following Monday, then cut the company's access. The company has not been named.
The case has been reported to Datatilsynet, the Danish Data Protection Agency, and police have opened an investigation. The government has also requested a full security review of the CPR system.
Why 8.8 million is more than Denmark's population
Denmark has about 6 million residents. The register also keeps people who have emigrated and people who have died, which is how 8.8 million records can be exposed out of roughly 11 million entries. People with protective registration, meaning name and address protection, were not exposed.
- Residents of Denmark (approx.)6 million
- Records exposed8.8 million
- Entries in the CPR (approx.)11 million
Source: The Copenhagen Post and Cybersecuritynews, accessed 2026-10-05
What data left the register
The two accounts we could fetch do not match, and neither links a government document.
| Data class | Copenhagen Post | Cybersecuritynews |
|---|---|---|
| Name, address, CPR number | Yes | Yes |
| Marital status, family relationships | Yes | Not listed |
| Birth registration details | Yes | Not listed |
| Church of Denmark affiliation | Yes | Not listed |
| Legal incapacitation information | Yes | Not listed |
The wider list matters. A CPR number is a ten-digit identifier that Danish banks, healthcare providers and agencies use to identify people. Paired with family links and a verified address, it gives a fraudster the details a verification script asks for. Cybersecuritynews says financial information, medical records and passwords have not been confirmed as compromised.
The access model is the story
Officials said this was not a known software vulnerability but abuse of permissions the company already held, per Cybersecuritynews. When a firm with legitimate access is misused, the register sees an authorised customer.
The gap between what the company needed and what its access allowed is the question the review will have to answer. Nothing we fetched says how many lookups were made, how fast, or whether rate limits existed.
Trusted access is also where other recent disclosures failed: Google's data centre figures leaked through a bad redaction, and the Anthropic diary case turned on who a company shares user data with.
What residents should do
Danish authorities warn of phishing. Criminals now hold names, addresses and CPR numbers, which make a fraudulent call or message sound credible. Officials advise not sharing passwords or sensitive data with unsolicited callers, even when they quote personal details correctly. Help is available from the Cyberhotline on +45 33 37 00 37 and at Sikkerdigital.dk.
The next milestones are Datatilsynet's findings and the register security review. Neither has a published date.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight ProductsAn unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.
- 03WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.
- 04Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited ListBuilds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.