Denmark CPR breach: 8.8 million identity records
company CPR access abused for ten days

Denmark CPR breach: 8.8 million identity records

Denmark's Central Person Register administration disclosed on 5 October 2026 that unauthorized parties reached personal data on about 8.8 million registered people. The entry point was not a public website. It was a private Danish company's legitimate permission to search the register.

What happened

The Ministry of Research, Education and Digitalisation said the access covered names, addresses, CPR numbers, and other data the company was allowed to query. People registered with name and address protection were not included.

The register holds about 11 million records, including living residents, people who have died, and people who have emigrated. The administration noticed irregular behaviour on the evening of Friday 2 October. The activity itself ran through September. Digitalisation minister Christina Egelund later told Ritzau the misuse lasted about ten days and that the company's access controls were not good enough.

The company's access has been cut off. The incident was reported to Datatilsynet, and police are investigating. The ministry has ordered a security review of the CPR system.

Who is affected

Anyone whose record sits in the Danish population register and was not under name-and-address protection is in scope. That is larger than Denmark's resident population because the register keeps historical records.

For an MSP, the lesson is vendor identity, not a Danish-only firewall rule. A partner account with broad lookup rights, weak monitoring, and a ten-day dwell time is enough to empty a high-value directory.

What to do now

  • Review every partner login that can query identity, payroll, or citizen-style directories, and cut unused ones today.
  • Alert on bulk lookups, off-hours queries, and exports from those accounts.
  • Treat any call or email that already knows a client's ID number, address, and name as a possible social-engineering lead.
  • Confirm third-party access reviews are on a calendar, not a once-a-year spreadsheet.

Source: Danish Ministry of Research, Education and Digitalisation, 5 October 2026. Official statement.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-105215: ZITADEL Login V1 account pre-hijack, CVSS 9.1
ZITADEL external IdP registration trusts forged identity fields