Denmark Central Person Register (CPR) Breach: Cyberattack Exposes Data of 8.8 Million via Company Account in 2026

Denmark Central Person Register (CPR) Breach: Cyberattack Exposes Data of 8.8 Million via Company Account in 2026

Executive Summary

On October 5, 2026, Danish authorities publicly disclosed a significant data breach affecting the Central Person Register (CPR), Denmark’s national population database. Attackers exploited a legitimate company account to access the names, addresses, and CPR numbers of approximately 8.8 million individuals, including current residents, former residents, and deceased persons. The breach, which lasted about 10 days in September 2026, was detected after a surge in automated queries triggered an internal investigation. The compromised data did not include the names and addresses of individuals with name-and-address protection status. Authorities have suspended the implicated company’s access, notified the Danish Data Protection Agency (Datatilsynet), and launched a police investigation. The incident underscores the risks associated with centralized national databases and third-party access, with long-term implications for identity theft and fraud due to the exposure of lifelong identifiers. Public advisories and extended digital security hotline hours have been implemented to assist affected individuals. This report is based solely on verified, primary-source content and does not include any speculative or unconfirmed information.

Technical Information

The breach of the Central Person Register (CPR) was executed through the abuse of a legitimate Danish company’s account, which had authorized access to the register for business purposes. Attackers leveraged this access to conduct a high volume of automated lookups, systematically harvesting names, addresses, and CPR numbers. The CPR number is a unique, 10-digit identifier assigned to every individual in Denmark, functioning similarly to a Social Security number in the United States. It is used extensively for healthcare, banking, and government services, and is intended to remain unchanged throughout a person’s life.

The attack did not involve malware deployment, phishing, or exploitation of software vulnerabilities. Instead, it relied on credential abuse and the exploitation of a trusted third-party relationship. The breach was detected when an employee of the register’s administration noticed unusual activity—specifically, a spike in automated queries—on October 2, 2026. Subsequent investigation over the weekend determined the scope of the breach, which was then reported to the Danish Data Protection Agency on October 4, 2026.

Technical analysis indicates that the attackers used automated scripts or tools to perform large-scale data harvesting. The method aligns with the following MITRE ATT&CK techniques: T1078 (Valid Accounts), T1199 (Trusted Relationship), T1119 (Automated Collection), and T1087 (Account Discovery). No evidence of malware, remote access trojans, or custom hacking tools has been disclosed in any primary source.

The breach is notable for its scale and the sensitivity of the data involved. The CPR system contains records on approximately 11 million individuals, including those who have moved abroad and the deceased. The 8.8 million records accessed represent about 80% of the total database. The compromised data did not include the names and addresses of individuals with name-and-address protection status, a safeguard that restricts disclosure to private companies and individuals.

Authorities responded by suspending the company’s access to the register, initiating a comprehensive security review, and launching a police investigation. Public advisories were issued, urging individuals to remain vigilant against fraud attempts, avoid sharing confidential information, and consider setting up credit warnings. The government extended the operating hours of its digital security hotline to provide additional support.

No attribution has been made regarding the identity or origin of the attackers. The incident is consistent with previous large-scale breaches of national registries in other countries, such as Argentina (2021), Turkey (2016), India (2018), and Israel (2006), all of which involved abuse of centralized databases and third-party access.

The technical evidence supporting these findings is robust, with high confidence in the attack vector, method, and sectoral impact, as all claims are corroborated by multiple independent, primary sources. Attribution remains low-confidence due to the absence of technical indicators or threat actor claims.

Affected Versions & Timeline

The breach affected the Central Person Register (CPR), Denmark’s national population database, which contains records on approximately 11 million individuals. The compromised data set includes names, addresses, and CPR numbers for about 8.8 million people, encompassing current residents, former residents, and deceased individuals. Data for those with name-and-address protection status was not included in the breach.

The verified timeline is as follows: The breach occurred over approximately 10 days in September 2026. Unusual activity was detected by register administration on Friday, October 2, 2026. The scope of the breach was determined over the weekend of October 3–4, 2026. The Danish Data Protection Agency was notified on Sunday, October 4, 2026. Public disclosure, suspension of company access, and the launch of a police investigation occurred on Monday, October 5, 2026.

Threat Activity

The threat activity centered on the abuse of a legitimate company account with authorized access to the CPR. Attackers conducted a very large number of automated lookups to identify and extract valid CPR numbers and associated personal data. The activity was detected due to the anomalous volume of queries, which deviated from normal usage patterns.

There is no evidence of malware, phishing, or exploitation of software vulnerabilities. The attack method relied entirely on credential abuse and the exploitation of a trusted third-party relationship. The lack of technical indicators or malware artifacts suggests a focus on stealth and the use of legitimate access pathways.

Authorities have not attributed the attack to any specific threat actor or group. The method is consistent with previous incidents targeting centralized government databases via supplier compromise and automated data harvesting. The exposure of CPR numbers, which are lifelong identifiers, significantly increases the risk of identity theft and fraud for affected individuals.

Mitigation & Workarounds

The following mitigation steps and workarounds have been implemented or recommended, prioritized by severity:

Critical: Immediate suspension of the compromised company’s access to the CPR database to prevent further unauthorized data extraction. Initiation of a comprehensive security review of the CPR system, including third-party access controls and monitoring.

High: Notification of the Danish Data Protection Agency and initiation of a police investigation to determine the full extent of the breach and identify responsible parties. Issuance of public advisories urging individuals to remain vigilant against fraud attempts, avoid sharing confidential information (such as passwords, MitID details, or one-time codes), and set up credit warnings via borger.dk.

Medium: Extension of digital security hotline hours to provide support and guidance to affected individuals. Review and enhancement of monitoring systems to detect anomalous activity and high-volume automated queries in real time.

Low: Ongoing assessment of whether affected individuals will require new CPR numbers, with current policy allowing for changes in cases of misuse.

Authorities have directed the public to official resources such as sikkerdigital.dk for fraud prevention advice and have emphasized the importance of not responding to unsolicited requests for confidential information, even if the requester appears to know personal details.

Indicators of Compromise

The following caveat applies: Indicators of compromise (IOCs) are point-in-time and should be validated before enforcement. At the time of writing, no public indicators of compromise (such as IP addresses, domains, URLs, or file hashes) have been disclosed in any primary source related to this incident.

References

https://therecord.media/denmark-breach-register-cyberattack https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html https://aa.com.tr/en/europe/personal-data-of-88m-people-accessed-in-denmark-security-incident/4078398

About Rescana

Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, monitor, and manage supplier-related cyber risks. Our platform enables continuous assessment of third-party access, detection of anomalous activity, and enforcement of access controls to reduce the risk of supplier compromise and data exposure. For questions about this report or to discuss how Rescana can support your organization’s risk management efforts, please contact us at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.