Denmark Says 8.8 Million Population Register Records Were Pulled Through One Company’s Lawful Access
Danish authorities say unauthorized parties used a private company’s lawful access to pull names, addresses and CPR numbers for about 8.8 million people from the national population register, and...
Denmark says unauthorized parties obtained the names, addresses and CPR numbers of about 8.8 million registered people by abusing a private Danish company’s lawful access to the Central Person Register, the national population database. The Ministry of Research, Education and Digitalization announced the incident on Monday, October 5, 2026. The register’s administration first noticed irregular behavior on Friday evening, and the minister has said the unauthorized access lasted about ten days, according to TV 2. No suspect has been named, and the company has not been named either.
Table Of Content
The figure counts registrations, not residents. The register holds about 11 million records, including people who have died or moved abroad, while Denmark has just over six million inhabitants, so the 8.8 million affected is about 80 percent of the register. TechCrunch reports that the breach “is thought to be the biggest in the country’s history.”
What Denmark has confirmed
The ministry’s release, published in Danish, relays the register administration’s findings and gives this sequence. The Friday and weekend steps come from its fact box.
| When | What the sources say |
|---|---|
| During September 2026 | The administration says the CPR system showed irregular behavior over the month. The minister puts the unauthorized access at about ten days, according to TV 2. |
| Friday, October 2, evening | The administration notices the irregular behavior. |
| Weekend of October 3 and 4 | It learns that unauthorized parties obtained names, addresses and CPR numbers for about 8.8 million registered people (living, emigrated, dead and others). |
| Sunday, October 4 | The register files a notification with Datatilsynet, the Danish Data Protection Agency. |
| Monday, October 5 | The ministry announces the incident and says the company’s access has been stopped. Minister Christina Egelund briefs two parliamentary committees, and the national special crime unit (NSK) is investigating. |
The ministry says its review shows the access did not cover the names and addresses of people registered with name and address protection. Its release lists names, addresses and CPR numbers, followed by the Danish abbreviation for “etc.”, and does not say what else was reached. TV 2 notes that the register can also hold marital status, birth registration details, family relationships, church membership, citizenship and guardianship information, and IT Security Guru adds that the ministry has not said which fields were accessed. TV 2 also reported that Egelund stressed that systems that use MitID, such as those in healthcare, are not immediately compromised. The ministry cautions that further mapping of the incident may refine the specific details.
How one company’s lawful access reached 8.8 million records
Datatilsynet says the notification it received on Sunday describes “a very large number of automated lookups against the CPR system with the aim of identifying valid CPR numbers” (my translation from Danish). BleepingComputer reads that as “brute-forcing to enumerate valid CPR numbers”; the agency’s own notice speaks only of automated lookups. It says it is examining what happened, how it was possible and who is responsible for the data processing involved.
Private firms are allowed to query the register, within limits. The ministry’s release explains that section 38 of the CPR Act lets a company receive data about a larger but delimited group of people it has already identified one by one, using either CPR number, birth date and name, or name and address, as long as it has a legitimate interest. The field list for private firms on the register’s site is exhaustive: current name and address, plus status data such as death and emigration. The ministry says the unauthorized access stayed within the information that private companies can reach, and TV 2 reports that Egelund described an unusually large number of lookups from a small Danish company over ten days, a company that otherwise had lawful access to the register. On that account, what was abnormal was the number of people asked about, not the kind of data.
Sofie Freja Christensen, cyber risk and offensive security manager at Conscia, took reader questions for TV 2 and was asked why no technical limit, rate limit or automatic alarm stopped such an abnormal number of lookups. She called it exactly the right question and said it has not been answered yet: “8.8 million, including dead and emigrated, is far more than any ordinary customer base. It should have been detected, and the current limits and alarms should be revisited so situations like this are detected quickly.” In the same Q&A, Johan Busse, chair of the Danish Data Ethics Council, answered a reader who asked why the whole system could be tapped by saying it should not have been possible, “if you ask me.”
The numbering rules show why a lookup channel is such an exposed place for this data. A CPR number is a birth date plus four digits, and Statistics Denmark’s documentation says numbers are issued per birth date, with about 540 numbers that carry a valid check digit (about 270 for each sex) used first. The public statements do not say what keyed the lookups or what a lookup returned for a guessed number, so treat the next figure as my arithmetic, not a reconstruction of the attack. About 540 candidates for each of roughly 55,000 birth dates (my assumption for about 150 years of dates) is at most about 30 million lookups. Spread over ten days that is around 35 requests per second, a modest rate for a script, and because numbers are handed out in sequence, a script could stop early on most dates. It is also the kind of sustained, wide-ranging pattern that Christensen says should have been detected.
This is not the first public case of a company’s CPR access being used this way. On December 15, 2025, the payroll platform Danløn said that on December 11 it had found that actors with unauthorized access through demo accounts had made 89,100 lookups in the CPR register “with CPR numbers the actors knew in advance” (my translation). It switched the function off and reported the case to Datatilsynet and to Styrelsen for Samfundssikkerhed (SAMSIK). Danløn’s release reports no sign of wider access to its systems. The October figure is about 99 times the December one (8.8 million against 89,100), though nothing public ties the two cases together. Oversight of company access has also drawn criticism before: a January 2020 Version2 report on company CPR subscriptions said the CPR office did not keep a running check on exactly which data firms retrieve or what they use it for.
What is still unknown
- Who is behind it. The ministry says the investigation is at an early stage and it cannot say who is responsible. Egelund said she does not rule out any lead, including an international one, according to TV 2. NSK deputy police inspector Nicklas Fallesen told the broadcaster, “The scope is quite large,” and that the case is a high priority.
- What the company’s role was. Busse noted that the role of the firm is not yet known and is part of what police are examining. Cybernews describes “stolen access,” while the official wording is that a lawful access was misused; credential theft, insider misuse and a compromised integration would call for different fixes.
- How many lookups, and what came back. Neither the number of requests nor the response the interface gave for a guessed number has been published.
- Whether anyone needs a new number. Egelund said it is too early to say. Statistics Denmark’s documentation says a CPR number stays with its holder and is never reused.
What to do now
The government’s guidance on sikkerdigital.dk is to expect messages and calls that use your personal details, avoid unexpected links, never share MitID credentials, one-time codes, passwords or card details, and call the sender back on its main number. If you have a concrete suspicion of fraud, you can place a credit warning on your CPR record, which makes it harder to take out credit in your name. SAMSIK’s cyber hotline (+45 33 37 00 37) is open from 8 a.m. to midnight for the coming days. Christensen told TV 2 readers that the main near-term risk is less a loan in your name than callers who use your CPR number to sound credible.
For companies, the message is that the CPR number can no longer vouch for identity. Dansk Industri (DI) said firms can no longer treat a CPR number as sufficient proof of a customer’s or employee’s identity and recommends MitID, security questions, customer-portal logins or other verification instead. Grit Munk of the engineers’ association IDA said the number should now be seen as “a really good tool for telling seven men called Jens Larsen apart from one another,” not as secure identification. Haderslev municipality has said residents who identify themselves by CPR number may now be asked for control questions.
Datatilsynet and the police are at an early stage, and Egelund has ordered a thorough security review of the CPR system with no set timeline. Several Folketing parties have backed the review, TV 2 reports. The question the experts keep returning to is how about 80 percent of an 11 million record register could be read through one small company’s legitimate access over about ten days before anything stopped it, and the authorities have not yet said what limits or alarms were in place.








No Comment! Be the first one.