At a Glance
| Organization | CPR-administrationen (Danish Central Person Register) |
| Data exposed | Names, addresses and CPR numbers, among other register data |
| People affected | About 8.8 million registered persons (living, emigrated, deceased and others) – official figure, still being mapped |
| Cause | Misuse of a private Danish company’s lawful search access to CPR |
| Disclosure status | Confirmed by the CPR administration; police investigation in an early phase |
| Source | Danish Ministry press release (UFM), October 2026 |
TL;DR
Unknown actors abused a Danish company’s lawful access to the national CPR register. As a result, they pulled names, addresses and CPR numbers for about 8.8 million people. Danish authorities have confirmed the Denmark CPR data breach, and police are now investigating.
What Was Exposed
The Central Person Register holds about 11 million records. These cover current residents, plus people who died or moved abroad. According to the authorities, the intruders reached names, addresses and CPR numbers for roughly 8.8 million of them.
However, one group escaped exposure. The official review found that the access did not include names and addresses of people with name and address protection.
The 8.8 million figure comes from the authorities themselves, so it is a confirmed count. Still, the ministry warns that further mapping may change the details. Readers should treat the numbers as preliminary.
How It Happened
This was not a classic hack of government servers. Instead, the attackers misused a private Danish company’s legitimate access to search the CPR system. Under section 38 of the CPR Act, private firms with a legitimate interest may receive certain register data. Normally, that access covers only people the company has already identified one by one.
The CPR administration spotted irregular activity that took place during September. It learned of the problem on the evening of Friday, October 2, 2026. Over the weekend, it confirmed the scale of the unauthorized access. So far, the ministry has not named the company, and nobody knows who stands behind the attack.
Who Is Affected
The breach touches almost everyone in the register. That group includes living residents, emigrants and deceased people. Denmark has faced smaller CPR incidents before. For example, in 2025 police arrested a former Copenhagen municipal employee suspected of accessing data on 1,742 people. By comparison, this Denmark CPR data breach is far larger.
What Affected People Should Do
The biggest risk now is targeted phishing and phone scams. Criminals can use a real name, address and CPR number to sound convincing. Because of this, the authorities urge everyone to stay alert in the coming weeks.
Practical Steps
- Never share passwords or login codes by phone, email or text message.
- Remember that a caller who knows your CPR number is not proof of a real bank or agency.
- Verify unexpected contacts through official phone numbers or websites.
- Read the guidance at sikkerdigital.dk.
- Call the Cyberhotline for digital security on +45 33 37 00 37. In the coming days, it stays open from 8:00 to 24:00.
Government Response
The CPR administration has cut off the company’s access. Together with specialists and other agencies, it is mapping the full sequence of events. It has also reported the case to Datatilsynet, the Danish Data Protection Agency. Meanwhile, police are investigating alongside relevant authorities.
Minister for Research, Education and Digitalisation Christina Egelund did not soften her words. “It is a deeply serious incident, which I have therefore also informed the Danish Parliament’s Business and Digitalisation Committee about,” she said, according to the translated statement. In addition, she has ordered a thorough security review of the CPR system. “I would urge all citizens to be vigilant now and in the time ahead,” she added.
The authorities say they have already launched measures to prevent similar incidents.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!