Nobody broke into Denmark’s population register. Someone borrowed a small company’s legitimate access to it and ran lookups for about ten days in September. By the time a CPR employee noticed the unusual activity on Friday, October 2, names, addresses and personal ID numbers for about 8.8 million people had been pulled. If a vendor holds an API key to your customer data, this is the scenario to rehearse.
The login was legitimate. The volume wasn’t. It took ten days for anyone to notice.
What happened
Denmark’s Central Person Register (CPR) announced on October 5 that unauthorized parties misused a Danish company’s lawful access to search the CPR system. They obtained names, addresses, CPR numbers and other details for roughly 8.8 million registered people, including living residents, people who have emigrated and people who have died. The system holds about 11 million records. CPR says the data does not include names and addresses of people registered with name and address protection.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Denmark’s data protection authority, Datatilsynet, received the breach notification on Sunday, October 4. It says the report describes a very large number of automated lookups made to identify valid CPR numbers. According to the ministry, the queries stayed within the categories of data private companies are allowed to receive. CPR has cut off the company’s access, police are investigating, and the ministry has ordered a full security review of CPR. Minister Christina Egelund told the Danish news agency Ritzau that the access ran for about ten days, and that the safeguards around this company’s access had not been good enough. Officials have not said who is behind it.
Why it matters
This is a third-party access failure, not an exploit. The credentials were real, and the per-query permissions were correct. What failed was volume and pattern: a partner suddenly enumerating most of a country, for days. Most organizations have the same exposure in their own partner APIs, data brokers and service accounts. And a list of names, addresses and national ID numbers is exactly what makes a phone scam sound official. That is why the Danish government is warning people not to trust callers just because they know those details.
What to do first
- List every partner, vendor and service account with query access to customer or employee records. Write down who owns each one.
- For each, set a volume baseline and alert on spikes: records per hour, distinct IDs per day, failed or “not found” lookups. Enumeration produces lots of misses.
- Rate-limit partner keys, and require partners to look up records they already hold identifiers for, not walk the ID space.
- If you have Danish staff or customers, tell your help desk and finance teams: a caller who knows someone’s name, address and CPR number is not verified by that.
Forward this
If you own a partner integration or a data API: Denmark lost 8.8 million records through one company’s valid login, over about ten days. Can we see it when a partner key suddenly pulls far more records than usual, and who gets the alert?
Details
- Who: Det Centrale Personregister (CPR), Denmark’s national civil registry. Details published by CPR and the Ministry of Research, Education and Digitalization (Forsknings-, Uddannelses- og Digitaliseringsministeriet).
- Scope: About 8.8 million registered people (living, emigrated, deceased and others) out of about 11 million records. Names, addresses, CPR numbers and more. People with name and address protection: names and addresses not included.
- How: Misuse of a private Danish company’s lawful CPR query access. Datatilsynet: very large number of automated lookups to identify valid CPR numbers.
- When: About ten days in September 2026. Spotted the evening of Friday, October 2. Reported to Datatilsynet Sunday, October 4. Announced Monday, October 5.
- Response: Company access blocked; police investigation; full CPR security review; Cyberhotline for digital safety +45 33 37 00 37, with extended hours (8:00–24:00 local) in the coming days; guidance at sikkerdigital.dk.
Hunt / verify
- Pull 90 days of query logs for each partner key and compare the daily distinct-record count with the contract’s expected volume.
- Look for sequential or near-sequential identifier lookups and high “not found” rates from any one key.
- Confirm partner keys are tied to known source IPs, and find out who at the partner can use them.
Slack paste: Denmark’s CPR registry: about 8.8M people’s names, addresses and ID numbers pulled through one company’s legitimate access over about 10 days in September. Our check: baseline and alert on partner/API key volume and enumeration patterns, rate-limit partner keys, and warn help desk that knowing someone’s CPR number does not verify a caller.
Sources
- https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger
- https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger
- https://www.datatilsynet.dk/presse-og-nyheder/nyhedsarkiv/2026/okt/datatilsynet-er-opmaerksom-paa-sag-om-opslag-i-cpr
- https://www.bt.dk/samfund/nye-detaljer-om-cpr-laekage-de-havde-adgang-gennem-ti-dage
- https://www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.