TRENDING
Close-up of the Rosetta Stone showing the Demotic script above and the Greek script below, the same text written in two different scripts
October 6, 2026
How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs
A row of green and grey fibre broadband street cabinets on a pavement beside a fence in Iver, England
October 6, 2026
BT’s TalkTalk Rescue Turns Telecom Continuity Into a New Merger-Control Ground
An ornate cast-iron wall mailbox with its door hanging open, stuffed with colorful flyers and a yellow flyer bulging out of the top slot
October 6, 2026
Google Stops Accepting Product Bug Reports for Its Open-Source Bounty, Citing Automated Submissions
Chronophotograph by Étienne-Jules Marey of a man riding a bicycle, showing five snapshots of the same ride taken at regular intervals
October 6, 2026
How to Find Slow Python Code With the Python 3.15 Tachyon Sampling Profiler
Close-up of an airport baggage tag reading Stockholm Arlanda and ARN
October 6, 2026
Cloudflare Traces Turns Distributed Tracing Into a Trust Decision at the Edge
06 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Shelves of old books fastened by iron chains in the Francis Trigge Chained Library in Grantham, England, a picture of data that can be read but not changed
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
October 5, 2026
Row of capsule hotel pods with white pillows and folded blankets, each capsule an idle sleeper packed into a shared rack
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
October 5, 2026
Denmark’s oldest church book, from Holmens parish, open on a stack of books; its handwritten pages record births between 1617 and 1639
Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
October 5, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 226 Posts
News 228 Posts
Learning Hub 198 Posts
Home/News/Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
News

Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access

Danish authorities say unauthorized parties used a private company’s lawful access to pull names, addresses and CPR numbers for about 8.8 million people from the national population register, and...

October 5, 2026 6 Min Read
11

Denmark says unauthorized parties obtained the names, addresses and CPR numbers of about 8.8 million registered people by abusing a private Danish company’s lawful access to the Central Person Register, the national population database. The Ministry of Research, Education and Digitalization announced the incident on Monday, October 5, 2026. The register’s administration first noticed irregular behavior on Friday evening, and the minister has said the unauthorized access lasted about ten days, according to TV 2. No suspect has been named, and the company has not been named either.

Table Of Content

  • What Denmark has confirmed
  • How one company’s lawful access reached 8.8 million records
  • What is still unknown
  • What to do now

The figure counts registrations, not residents. The register holds about 11 million records, including people who have died or moved abroad, while Denmark has just over six million inhabitants, so the 8.8 million affected is about 80 percent of the register. TechCrunch reports that the breach “is thought to be the biggest in the country’s history.”

What Denmark has confirmed

The ministry’s release, published in Danish, relays the register administration’s findings and gives this sequence. The Friday and weekend steps come from its fact box.

When What the sources say
During September 2026 The administration says the CPR system showed irregular behavior over the month. The minister puts the unauthorized access at about ten days, according to TV 2.
Friday, October 2, evening The administration notices the irregular behavior.
Weekend of October 3 and 4 It learns that unauthorized parties obtained names, addresses and CPR numbers for about 8.8 million registered people (living, emigrated, dead and others).
Sunday, October 4 The register files a notification with Datatilsynet, the Danish Data Protection Agency.
Monday, October 5 The ministry announces the incident and says the company’s access has been stopped. Minister Christina Egelund briefs two parliamentary committees, and the national special crime unit (NSK) is investigating.

The ministry says its review shows the access did not cover the names and addresses of people registered with name and address protection. Its release lists names, addresses and CPR numbers, followed by the Danish abbreviation for “etc.”, and does not say what else was reached. TV 2 notes that the register can also hold marital status, birth registration details, family relationships, church membership, citizenship and guardianship information, and IT Security Guru adds that the ministry has not said which fields were accessed. TV 2 also reported that Egelund stressed that systems that use MitID, such as those in healthcare, are not immediately compromised. The ministry cautions that further mapping of the incident may refine the specific details.

How one company’s lawful access reached 8.8 million records

Datatilsynet says the notification it received on Sunday describes “a very large number of automated lookups against the CPR system with the aim of identifying valid CPR numbers” (my translation from Danish). BleepingComputer reads that as “brute-forcing to enumerate valid CPR numbers”; the agency’s own notice speaks only of automated lookups. It says it is examining what happened, how it was possible and who is responsible for the data processing involved.

Private firms are allowed to query the register, within limits. The ministry’s release explains that section 38 of the CPR Act lets a company receive data about a larger but delimited group of people it has already identified one by one, using either CPR number, birth date and name, or name and address, as long as it has a legitimate interest. The field list for private firms on the register’s site is exhaustive: current name and address, plus status data such as death and emigration. The ministry says the unauthorized access stayed within the information that private companies can reach, and TV 2 reports that Egelund described an unusually large number of lookups from a small Danish company over ten days, a company that otherwise had lawful access to the register. On that account, what was abnormal was the number of people asked about, not the kind of data.

Sofie Freja Christensen, cyber risk and offensive security manager at Conscia, took reader questions for TV 2 and was asked why no technical limit, rate limit or automatic alarm stopped such an abnormal number of lookups. She called it exactly the right question and said it has not been answered yet: “8.8 million, including dead and emigrated, is far more than any ordinary customer base. It should have been detected, and the current limits and alarms should be revisited so situations like this are detected quickly.” In the same Q&A, Johan Busse, chair of the Danish Data Ethics Council, answered a reader who asked why the whole system could be tapped by saying it should not have been possible, “if you ask me.”

The numbering rules show why a lookup channel is such an exposed place for this data. A CPR number is a birth date plus four digits, and Statistics Denmark’s documentation says numbers are issued per birth date, with about 540 numbers that carry a valid check digit (about 270 for each sex) used first. The public statements do not say what keyed the lookups or what a lookup returned for a guessed number, so treat the next figure as my arithmetic, not a reconstruction of the attack. About 540 candidates for each of roughly 55,000 birth dates (my assumption for about 150 years of dates) is at most about 30 million lookups. Spread over ten days that is around 35 requests per second, a modest rate for a script, and because numbers are handed out in sequence, a script could stop early on most dates. It is also the kind of sustained, wide-ranging pattern that Christensen says should have been detected.

This is not the first public case of a company’s CPR access being used this way. On December 15, 2025, the payroll platform Danløn said that on December 11 it had found that actors with unauthorized access through demo accounts had made 89,100 lookups in the CPR register “with CPR numbers the actors knew in advance” (my translation). It switched the function off and reported the case to Datatilsynet and to Styrelsen for Samfundssikkerhed (SAMSIK). Danløn’s release reports no sign of wider access to its systems. The October figure is about 99 times the December one (8.8 million against 89,100), though nothing public ties the two cases together. Oversight of company access has also drawn criticism before: a January 2020 Version2 report on company CPR subscriptions said the CPR office did not keep a running check on exactly which data firms retrieve or what they use it for.

What is still unknown

  • Who is behind it. The ministry says the investigation is at an early stage and it cannot say who is responsible. Egelund said she does not rule out any lead, including an international one, according to TV 2. NSK deputy police inspector Nicklas Fallesen told the broadcaster, “The scope is quite large,” and that the case is a high priority.
  • What the company’s role was. Busse noted that the role of the firm is not yet known and is part of what police are examining. Cybernews describes “stolen access,” while the official wording is that a lawful access was misused; credential theft, insider misuse and a compromised integration would call for different fixes.
  • How many lookups, and what came back. Neither the number of requests nor the response the interface gave for a guessed number has been published.
  • Whether anyone needs a new number. Egelund said it is too early to say. Statistics Denmark’s documentation says a CPR number stays with its holder and is never reused.

What to do now

The government’s guidance on sikkerdigital.dk is to expect messages and calls that use your personal details, avoid unexpected links, never share MitID credentials, one-time codes, passwords or card details, and call the sender back on its main number. If you have a concrete suspicion of fraud, you can place a credit warning on your CPR record, which makes it harder to take out credit in your name. SAMSIK’s cyber hotline (+45 33 37 00 37) is open from 8 a.m. to midnight for the coming days. Christensen told TV 2 readers that the main near-term risk is less a loan in your name than callers who use your CPR number to sound credible.

For companies, the message is that the CPR number can no longer vouch for identity. Dansk Industri (DI) said firms can no longer treat a CPR number as sufficient proof of a customer’s or employee’s identity and recommends MitID, security questions, customer-portal logins or other verification instead. Grit Munk of the engineers’ association IDA said the number should now be seen as “a really good tool for telling seven men called Jens Larsen apart from one another,” not as secure identification. Haderslev municipality has said residents who identify themselves by CPR number may now be asked for control questions.

Datatilsynet and the police are at an early stage, and Egelund has ordered a thorough security review of the CPR system with no set timeline. Several Folketing parties have backed the review, TV 2 reports. The question the experts keep returning to is how about 80 percent of an 11 million record register could be read through one small company’s legitimate access over about ten days before anything stopped it, and the authorities have not yet said what limits or alarms were in place.

Tags:

Data BreachesData PrivacyDenmarkGDPRGovernment CybersecurityThird-Party Risk

Share

Close-up of the Rosetta Stone showing the Demotic script above and the Greek script below, the same text written in two different scripts
Previous Post

How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs

Row of capsule hotel pods with white pillows and folded blankets, each capsule an idle sleeper packed into a shared rack
Next Post

Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
05 Oct
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
05 Oct
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
Trending
October 5, 2026
How to Use frozendict in Python 3.15 to Freeze Config and Cache Dictionary Arguments
October 5, 2026
Kubernetes Node Swap Turns Idle Agent Memory Into a Density Bet With No Wake-Up Test
October 5, 2026
Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
October 5, 2026
How to Prepare Your Python Code for the Python 3.15 UTF-8 Default and Fix Windows Encoding Bugs
October 5, 2026
BT’s TalkTalk Rescue Turns Telecom Continuity Into a New Merger-Control Ground
October 5, 2026
Google Stops Accepting Product Bug Reports for Its Open-Source Bounty, Citing Automated Submissions

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026