The Denmark CPR breach exposed the names, addresses and CPR numbers of roughly 8.8 million people, after unauthorised parties searched the register for about ten days in September 2026. Denmark’s CPR administration spotted irregular activity on the evening of Friday 2 October and closed the access. Police and the data protection authority are investigating.
Who Is in the 8.8 Million, and Who Is Not
The figure is larger than Denmark’s population because the register is historical. The CPR system holds records for about 11 million people, and the Denmark CPR breach covers roughly 8.8 million of them: residents, people who have emigrated, and people who have died.
- Data taken: name, address and CPR number, the ten-digit Danish personal identification number.
- Not affected: people who have registered name and address protection with the authorities. The CPR administration’s own notice says their details were not included.
- Not taken: passwords, MitID credentials, bank details or health records, none of which sit in the CPR register.
How One Company’s Lawful Access Became a Breach
Nobody broke into the CPR system itself. Private firms with a justified interest can be granted the right to search the register under section 38 of the Danish CPR Act, and the attackers misused one such company’s legitimate access.
Christina Egelund, Denmark’s Minister for Research, Education and Digitalisation, said in the ministry’s statement of 5 October 2026 that “det er en dybt alvorlig haendelse” – “it is a deeply serious incident”. She also conceded that the safeguards failed, telling Danish media that the security measures around this company’s access to CPR had not been good enough and that it should not have been possible. The company has not been named by the authorities.
The Timeline, Hour by Hour
- September 2026: the unauthorised searches run for approximately ten days.
- Friday 2 October 2026, evening: a CPR administration employee notices irregular activity in the system.
- Saturday 3 October 2026: the activity is confirmed as a security incident and the company’s access is closed.
- Monday 5 October 2026: the CPR administration and the ministry publish the incident, report it to the Danish Data Protection Agency, and confirm a police investigation.
Where the Investigation Stands as of 6 October 2026
The access is closed and the investigation is open. The CPR administration has blocked the company’s access, notified Datatilsynet, the Danish Data Protection Agency, introduced preventive measures and begun a full security review of the register. Danish police are investigating alongside other authorities. No arrests have been announced.
What a Leaked CPR Number Can and Cannot Do
The main risk is convincing impersonation rather than direct account theft. Someone holding a person’s name, address and CPR number can make a phone call or an email look official, because quoting those three details is how many Danish institutions open a conversation.
Security specialists quoted by Danish and international outlets describe the practical risks as phishing messages that cite the CPR number to push victims towards fake Borger.dk or bank login pages, callers posing as the tax authority SKAT or the benefits agency Udbetaling Danmark, and attempts to talk a bank into an account change. What the data does not contain is a MitID credential, so Denmark’s two-factor login cannot be bypassed with the leaked records alone.
That distinction matters, and it is the reason the official advice is about vigilance rather than password resets. Our earlier report on the IDScan data breach covered the same pattern, where identity details leak through a supplier rather than the institution people trust.
What to Do if You Are in the Danish Register
- Treat any unexpected call, email or text that quotes your CPR number as suspect, even if the sender also knows your name and address.
- Never give out a password, a bank code or a MitID approval over the phone or by email. No Danish authority or bank will ask for one that way.
- Approach the organisation yourself, using a number or an address you already have, rather than a link or a number supplied in the message.
- Read the official guidance at sikkerdigital.dk, the Danish government’s digital security site.
- Call the Danish Cyberhotline on +45 33 37 00 37 if you think you have been targeted or have already handed over information.
There is no credit freeze or identity-monitoring offer attached to this incident, and no sign-up page. The authorities have not said they will write to affected people individually, which is a practical problem when the affected group is larger than the living population.
Questions Denmark Has Not Answered
Four things remain unknown as of 6 October 2026. The company whose access was abused has not been named. Who carried out the searches has not been established. There is no public statement on whether the data has been sold, published or posted anywhere. And the authorities have not said whether individual notifications will be sent, or what will change about section 38 access as a result.
Frequently Asked Questions
How Many People Does the Denmark CPR Breach Affect?
About 8.8 million people registered in Denmark’s Central Person Register, including current residents, former residents who have emigrated and people who have died. The register holds roughly 11 million records in total.
What Information Was Taken?
Names, addresses and CPR numbers. No passwords, MitID credentials, bank details or health information were in the data, because the CPR register does not hold them.
Was Anyone Excluded From the Breach?
Yes. The CPR administration says people who have registered name and address protection were not affected.
Can Someone Empty My Bank Account With My CPR Number?
Not with the leaked data alone. A CPR number is not a password and does not provide a MitID approval, so Denmark’s two-factor login still stands in the way. The realistic risk is a convincing phishing call or email that uses your details to win trust.
Who Is Investigating?
Danish police, working with other authorities, and the case has been reported to Datatilsynet, the Danish Data Protection Agency. The CPR administration has also started a security review of the register.




