A partner’s login pulled 8.8 million Danish records — check what your vendor keys can pull

By George Bailey   Published: 10/06/26   4 min read

Nobody broke into Denmark’s population register. Someone borrowed a small company’s legitimate access to it and ran lookups for about ten days in September. By the time a CPR employee noticed the unusual activity on Friday, October 2, names, addresses and personal ID numbers for about 8.8 million people had been pulled. If a vendor holds an API key to your customer data, this is the scenario to rehearse.

The login was legitimate. The volume wasn’t. It took ten days for anyone to notice.

What happened

Denmark’s Central Person Register (CPR) announced on October 5 that unauthorized parties misused a Danish company’s lawful access to search the CPR system. They obtained names, addresses, CPR numbers and other details for roughly 8.8 million registered people, including living residents, people who have emigrated and people who have died. The system holds about 11 million records. CPR says the data does not include names and addresses of people registered with name and address protection.

Denmark’s data protection authority, Datatilsynet, received the breach notification on Sunday, October 4. It says the report describes a very large number of automated lookups made to identify valid CPR numbers. According to the ministry, the queries stayed within the categories of data private companies are allowed to receive. CPR has cut off the company’s access, police are investigating, and the ministry has ordered a full security review of CPR. Minister Christina Egelund told the Danish news agency Ritzau that the access ran for about ten days, and that the safeguards around this company’s access had not been good enough. Officials have not said who is behind it.

Why it matters

This is a third-party access failure, not an exploit. The credentials were real, and the per-query permissions were correct. What failed was volume and pattern: a partner suddenly enumerating most of a country, for days. Most organizations have the same exposure in their own partner APIs, data brokers and service accounts. And a list of names, addresses and national ID numbers is exactly what makes a phone scam sound official. That is why the Danish government is warning people not to trust callers just because they know those details.

What to do first

Forward this

If you own a partner integration or a data API: Denmark lost 8.8 million records through one company’s valid login, over about ten days. Can we see it when a partner key suddenly pulls far more records than usual, and who gets the alert?

Details

Hunt / verify

Slack paste: Denmark’s CPR registry: about 8.8M people’s names, addresses and ID numbers pulled through one company’s legitimate access over about 10 days in September. Our check: baseline and alert on partner/API key volume and enumeration patterns, rate-limit partner keys, and warn help desk that knowing someone’s CPR number does not verify a caller.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.