Denmark CPR breach exposes 8.8 million identity records
Lawful company lookup abused across the national register

Denmark CPR breach exposes 8.8 million identity records

Denmark's Central Person Register disclosed that unauthorized users abused a private company's lawful search access and took names, addresses and CPR numbers for about 8.8 million registered people. The register noticed irregular September activity on Friday 2 October and confirmed the scale over the weekend.

What happened

CPR numbers are Denmark's national identifier. Private firms with a legitimate interest can look people up. Attackers used one Danish company's legitimate access rather than a software flaw in the register itself.

Officials told a Tuesday briefing the account made well over 14 million lookup attempts across ten days in September. About 8.8 million of those returned a record. The activity surfaced when the administration billed the firm for the lookups.

The register holds about 11 million records, including people who have died or moved abroad, which is why the count exceeds Denmark's population of about 6 million. People who had registered for name and address protection were not included.

Who is affected

  • About 8.8 million people registered in CPR, living, deceased, or living abroad.
  • People in Greenland who use CPR numbers for healthcare, tax and banking sit in the same register.
  • Any firm that stores Danish CPR numbers, or that has its own bulk lookup rights into the register.

What to do now

If you hold Danish customer or employee data, assume CPR numbers, names and addresses from this set may be in criminal hands, and tighten lookup accounts that can query national identity systems.

Digitization minister Christina Egelund said it is too early to say whether Denmark will reissue CPR numbers. Police and the Data Protection Agency are investigating. The company's access has been cut.

Source: SecurityWeek, citing the Danish Ministry of Higher Education and Science. 8.8 million impacted by Denmark CPR breach. Primary statement: ministry notice, 5 October 2026.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Engineer sentenced to 32 months for locking 3,284 PCs
Insider password reset and failed 20-bitcoin extortion