On 5 October 2026, Denmark's Forsknings-, Uddannelses- og Digitaliseringsministeriet (Ministry of Research, Education and Digitalisation), under minister Christina Egelund, announced that unauthorised parties had accessed names, addresses, CPR numbers and related fields for about 8.8 million of roughly 11 million persons registered in Det Centrale Personregister (CPR) — Denmark's national civil registration system. The ministry says the access came from misuse of a Danish company's lawful ability to search the CPR system, not from a disclosed vulnerability in the register itself.
There is no CVE and this is not a CISA KEV listing. It is also a separate incident from the DTU (Technical University of Denmark) breach covered elsewhere, and from a 2025 Copenhagen Municipality case involving a student assistant's CPR lookup misuse.
The ministry and Datatilsynet (the Danish data protection authority) are still mapping the facts. The ministry has reserved the right to consolidate the published figures as the investigation continues. This advisory sticks to dated official wording and clearly attributed secondary reporting.
Technical Information
What the ministry says happened
In its 5 October 2026 press release (also mirrored by the CPR administration on cpr.dk), the ministry stated that by misusing a Danish company's lawful access to search information in the CPR system, unauthorised persons obtained access to names, addresses, CPR numbers and related data for about 8.8 million registered citizens.
Key official points:
- When: activity during September 2026. The CPR administration became aware of irregular behaviour on the evening of Friday 2 October 2026. Over the weekend of 3–4 October it formed a clearer picture of the scale.
- Duration: the minister, quoted via Ritzau, said the access lasted about 10 days in September and was spotted by a CPR administration employee.
- Company: not named. The minister, via Ritzau and TV 2, described it as a small ("mindre" / "lille") Danish company. How unauthorised parties obtained use of that company's access — credentials, system compromise, insider or otherwise — has not been disclosed. Do not treat any of those paths as confirmed.
- Actor: unknown. The ministry says the investigation is at an early stage and it is not possible to say who is behind it. The minister has said authorities are not ruling out an international dimension (via TV 2).
- Legal framing: the ministry places the data within the information private companies may access, referring to CPR Act §38. It has not disclosed whether the abused channel was a §38 bulk/subscription-style arrangement or a §39 electronic single-lookup route. Do not invent a channel.
What Datatilsynet says
Datatilsynet's 5 October 2026 notice states that it received the CPR register's notification on Sunday 4 October. According to that notification, a very large number of automated lookups were made against the CPR system to identify valid CPR numbers. Datatilsynet says the numbers were "allegedly" ("angiveligt") retrieved and that it has not yet assessed the case. Its review will cover what happened, how it could happen, and who is the data controller for the processing.
BleepingComputer (5 October 2026) characterised that pattern as "some form of brute-forcing to enumerate valid CPR numbers." That wording is BleepingComputer's reading, not Datatilsynet's. Attribute "brute-force" only if you need it, and only to BleepingComputer.
An unexplained official tension on CPR numbers
CPR's own public guidance on person subscriptions states that CPR numbers are never disclosed to private parties ("Der videregives aldrig personnumre til private"); the CPR number is typically the identifier a company submits, not a field returned to it.
At the same time, the ministry says CPR numbers were among the data accessed, and Datatilsynet relays that the lookups aimed to identify valid CPR numbers.
No official source has explained how those two statements fit together. This advisory presents both as published and does not fill the gap.
What is not confirmed
- That data was copied, retained, shared, sold, dumped or "leaked" — use accessed. Danish media sometimes say "læk"; do not echo that as fact.
- The company's name, intent, or how its access was obtained.
- Who the actor is.
- Whether the CPR numbers of name/address-protected persons were reached (only their names and addresses are confirmed excluded).
- Individual notification of affected people, or whether new CPR numbers will be issued (the minister said it is too early to say, via Ritzau).
- That wider register fields (for example marital status, kinship, church membership or citizenship, which secondary outlets list as part of CPR's contents) were accessed. Official scope stays within what private companies may access under §38.
Affected Product Versions
This incident is not a versioned product vulnerability. Scope is register- and access-based:
| Item | Detail | Source |
|---|---|---|
| System | Det Centrale Personregister (CPR), Denmark's national civil registration system, operated by the CPR administration | Ministry / cpr.dk, 5 Oct 2026 |
| Population accessed | About 8.8 million of about 11 million registered persons (living, emigrated, deceased and others). Denmark's resident population is about 6 million, so 8.8M is larger than living residents alone | Ministry; THN citing Statistics Denmark for the resident figure |
| Data fields (official) | Names, addresses, CPR numbers "etc.", within the information private companies may access | Ministry |
| Legal reference cited | CPR Act §38 (LBK nr. 1010 of 23 June 2023). §39 single lookups exist in the statute but are not cited in the ministry release as the abused path | Ministry; retsinformation.dk |
| Protected persons | Names and addresses of people with name and address protection (navne- og adressebeskyttelse) are not included. Whether their CPR numbers were reached is not stated | Ministry; gap noted by THN |
| Access holder | An unnamed private Danish company with lawful CPR search access; described as small by the minister via Ritzau / TV 2 | Ministry; Ritzau / TV 2 |
| Not in scope of this advisory | DTU breach; 2025 Copenhagen Municipality student-assistant CPR misuse | Separate incidents |
§38, in outline, lets businesses receive defined CPR data about a larger group of persons they have previously identified individually (by CPR number, date of birth plus name, or address plus name). §40 lets the ministry set terms for those disclosures, including security measures, and restricts onward sharing of data obtained under §§38–39 without a legal basis or ministry permission. The 2023 consolidated statute named a different parent ministry; the 2026 statement comes from Forsknings-, Uddannelses- og Digitaliseringsministeriet, so organisational responsibility has moved since that consolidation.
Workaround and Mitigation
Official response so far (as of 6 October 2026):
- Company access stopped. The CPR administration has stopped the company's access.
- Preventive initiatives. The ministry says initiatives have already been launched to prevent similar incidents; the details are not disclosed.
- Security review. Minister Christina Egelund has ordered a thorough security review of the CPR system, with no fixed deadline reported.
- Datatilsynet. Notified on Sunday 4 October; reviewing the case, assessment not yet complete.
- Police. A criminal investigation is under way. Media (TV 2, Ritzau / Politiken) report that Denmark's National Special Crime Unit (NSK) is leading and that Deputy Police Inspector Nicklas Fallesen described the work as "very early in the investigation." No politi.dk primary statement was located for this advisory.
- Parliamentary briefing. The minister informed Parliament's Business and Digitalisation Committee (and, per TV 2, briefed that committee and the Foreign Affairs and Defence Committee on 5 October).
- Citizen guidance. The ministry advises people never to give passwords or confidential information over phone or email even if the other party appears to know their name, address and CPR number, and points to sikkerdigital.dk and the Cyberhotline (+45 33 37 00 37), which extended hours to 08:00–24:00 on 5 October. Setting a credit warning (kreditadvarsel) via borger.dk / sikkerdigital.dk is among the publicly recommended steps.
The minister, via Ritzau, said it is clear that security measures around this company's CPR access "have not been good enough," and agreed that warning signs should have appeared given the duration. That is a minister's assessment of the access holder's safeguards, not a root-cause finding about credentials versus insider activity.
No official source has announced individual notification of affected persons or a decision to reissue CPR numbers.
Indicators of Compromise
None published. As of 6 October 2026, the ministry, CPR administration, Datatilsynet and police have not released IP addresses, domains, file hashes, account identifiers or tooling related to this incident.
No reputable source maps the activity to MITRE ATT&CK technique IDs. No actor is named.
Honest empty — do not invent IoCs or ATT&CK mappings for this advisory.
Why this matters for third-party / vendor risk
On the ministry's account, this was not a core register "hack" through a published vulnerability. It was misuse of a third party's lawful, privileged lookup access, lasting about ten days before detection, with the minister publicly saying safeguards around that company's access were not good enough. Any organisation that relies on suppliers, service bureaus or processors with legitimate access to national registries, KYC stores or other identity data has the same class of exposure: the access holder is part of the attack surface, and annual questionnaires alone will not catch a short, high-volume abuse window.
Practical themes for TPRM teams — framed as general practice, not as claims about this unnamed company's root cause — include inventorying every party with registry or identity-data access (including fourth parties), monitoring lookup volume and enumeration patterns against each holder's baseline, enforcing scoped and rate-limited access with time-boxed credentials, and requiring continuous monitoring plus prompt incident notification from those access holders. Treat national ID numbers as fraud fuel, not as authenticators: processes that accept a CPR number (or peer national ID) as sufficient proof of identity deserve a fresh look, at suppliers and in-house.
Book a demo if you want help mapping which of your vendors hold privileged registry or identity-data access, and putting continuous monitoring around those access holders.
Forwardable blurb for your TPRM / vendor-risk owner:
"Please confirm which national registries or identity / KYC data sources you (or your sub-processors) access on our behalf, under what legal basis and through which channels. How are those credentials issued, stored, rotated and bound? What per-client rate limits, volume caps and anomaly alerts do you run against lookup baselines, and how quickly are spikes reviewed? Can you detect enumeration patterns (high miss rates, sequential identifiers)? What is your notification SLA to us and to the registry owner if your access is misused, and when was the last independent security review of that integration?"
Sources
- Forsknings-, Uddannelses- og Digitaliseringsministeriet press release, 5 October 2026 (authoritative)
- CPR administration news mirror, 5 October 2026
- Datatilsynet notice, 5 October 2026
- CPR Act, LBK nr. 1010 of 23 June 2023 (§§38–40)
- cpr.dk guidance on person subscriptions ("CPR numbers are never disclosed to private parties")
- BleepingComputer, 5 October 2026 ("brute-force" characterisation attributed here only)
- The Hacker News, 6 October 2026
- Ritzau / nyheder.dk and TV 2 coverage, 5 October 2026 (minister quotes on duration, small company, NSK investigation; no politi.dk primary statement located)
- Version2, 5 October 2026 (restates ministry facts; company not named)



