Denmark: attackers took CPR data on 8.8 million people via a company's access

07.10.2026 3 min 58

Attackers obtained the names, addresses and personal identity numbers of about 8.8 million people from Denmark's Central Person Register (CPR), the Danish government announced on October 5. They did not break into the register itself: they misused a private Danish company's legitimate access to look up people in the CPR. The register holds about 11 million records, so roughly four out of five entries were affected, including, according to Help Net Security, people who have died or moved abroad.

What happened

Denmark's CPR is the backbone of public life: the 10-digit CPR number identifies a person across public services, banks and the MitID digital ID. Some private companies are also allowed to look up data in it. According to the CPR administration, the attackers used one such company's access and stayed within what private companies are allowed to see. People registered with name and address protection were not affected.

The administration noticed irregular activity in September on the evening of Friday, October 2, worked out its scale over the weekend and reported it to the Danish Data Protection Agency on Sunday, October 4. It has cut off the company's access, and the police are investigating. The company has not been named. "This is a deeply serious incident," said Christina Egelund, Minister for Research, Education and Digitalisation, who briefed the Danish parliament's committee on business and digitalisation.

The official statement lists names, addresses and CPR numbers. The Copenhagen Post reported a wider set, including marital status and family relations; the government has not confirmed those categories.

Why this matters

A CPR number is not a password, and on its own it does not open a MitID login or a bank account. But together with a name and an address it is exactly what fraudsters need to sound official on the phone or in an email: "We're calling from the bank about your CPR number." The authorities have warned of such attempts and repeat the basic rule: never hand over passwords, MitID codes or other confidential information over the phone, by email or through similar channels.

The case also shows a weak point that many countries share. A national register can be well protected and still leak through the thousands of companies that are allowed to query it, because each of those accounts is a door.

What people in Denmark should do

  • Treat calls and messages that quote your CPR number with suspicion. Knowing it no longer proves the caller is your bank or a public authority.
  • Never approve a MitID request you did not start yourself, and never read out codes.
  • Check official guidance on sikkerdigital.dk, the government's site for digital security advice.

denmarkcprdata breachpersonal dataphishingidentity theftmitidgovernment

Read also