Cybersecurity 4 min read

Intruders Used One Company's Legal Access to Reach 8.8 Million Danish ID Records

Names, addresses and CPR numbers were obtained from the national population register over about ten days in September. The minister says safeguards were not solid enough.

Priya Nair
Data, AI Governance & Policy Analyst
Published 7 Oct 2026, 6:58 PM (SGT)
Share:
Copenhagen City Hall and its square at dusk Copenhagen City Hall and its square at dusk Photo by LaustLauridsen on Pixabay
Advertisement

7 OCT 2026 — Over part of September, outsiders obtained the names, addresses and personal ID numbers of about 8.8 million people from Denmark's national population register. They used access the government had granted to a private company, and they did not break through the register's defences. They misused an authorised door at a volume nobody noticed for days.

Denmark's digitalisation ministry disclosed the incident on 5 October. The CPR, the Central Person Register, holds about 11 million records, including people who have died or moved abroad. The breach covers roughly four in five of them.

What the ministry has confirmed

The ministry says the CPR administration noticed irregular activity "during September" on the evening of Friday 2 October. Over the weekend it established that unauthorised people had obtained names, addresses and CPR numbers of about 8.8 million registered people, among other details.

The access came through "a private Danish company's lawful access to search information in the CPR system". People registered with name and address protection were not included. The company's access has been stopped, the case has been reported to the Danish Data Protection Agency, and police are investigating. The ministry says it is too early to say who is behind it.

~8.8mPeople whose names, addresses and CPR numbers were taken
~11mRecords in the register, including the dead and emigrants
~10 daysHow long the access ran in September, per the minister
UnknownWho is responsible; the police investigation is at an early stage

A legal door, used at scale

Danish law lets private companies with a legitimate interest receive data from the CPR. Under section 38 of the CPR Act, as the ministry summarises it, a company can obtain details about a defined group of people it has already identified one by one: by CPR number, by date of birth and name, or by name and address.

That design assumes a company asks about people it already knows. The ministry's account suggests the access was used to reach most of the register instead. It has not explained how the lookups were made at that volume or why they were not flagged sooner.

The minister on what failed

Christina Egelund, the minister for research, education and digitalisation, called it "a deeply serious incident" and said she had informed parliament's business and digitalisation committee. In comments reported by the news agency Ritzau, she said the access ran for about ten days through a smaller company and was spotted by a CPR administration employee on 2 October.

Advertisement

"It should not have been possible," she said, and agreed that warning lights should have gone off over such a long period. "It is clear to me that the security measures that should surround this type of access have not been solid enough." She declined to say whether the company itself was suspected of wrongdoing, citing the investigation.

New controls on CPR access are already in place, the ministry says, and a full security review of the system has been ordered.

What the data enables

Names, addresses and ID numbers are the details an impostor uses to sound official. The ministry's warning follows from that: never give out passwords or other confidential information by phone or email, "even if the recipient apparently knows your name, address and CPR number". It has pointed residents to the government's sikkerdigital.dk advice service and extended the national cyber hotline's hours.

The Data Protection Agency confirmed on 5 October that it received the CPR administration's notification on Sunday and said it could not yet assess the case, TV 2 reported.

What to watch

Two questions remain open: who was using the company's access, and whether the company knew. The answer will shape the review. A rogue insider or stolen credentials would point to tighter monitoring. A company that turns out to have been a front would point to the rules for who gets access at all.

Advertisement
Priya Nair
Data, AI Governance & Policy Analyst

Priya Nair covers AI governance, data protection, privacy, and digital trust topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Priya Nair is a RECATOOLS editorial persona for AI governance, privacy, and digital trust coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement