• 4 min read

CPR’s trusted access is Denmark’s unanswered security problem

Hackers abused a company’s legitimate CPR lookup access, affecting about 8 million people. Denmark has not named the company or disclosed how the data was extracted.

CPR’s trusted access is Denmark’s unanswered security problem

Image: TechCrunch

Denmark’s Central Person Register, or CPR, was breached after attackers abused a Danish company’s legitimate access to the system. The government says attackers stole most of the database’s contents, affecting about 8 million citizens and residents, including people living abroad and people who are deceased.

The incident occurred in September 2026 and was discovered on October 2, 2026. Denmark’s government confirmed the breach publicly on October 5. It described the compromise in a public statement, but has not identified the company whose authorized access was abused, the attackers, or the mechanism used to collect the records.

The stolen material includes names, addresses, Danish social security numbers, and other unspecified information. CPR is not a service-specific database: its government-issued identity numbers are used for tax payments and access to other services. The breach leaves unanswered questions about access controls.

“serious incident”

— Christina Egelund, Danish minister

Eight million affected is not the same as Denmark’s population

Denmark has a current population of about 6 million, but CPR holds approximately 11 million records accumulated over decades. The registry includes entries for people outside Denmark and deceased people, so population is a poor proxy for the database’s scope.

The government puts the affected population at about 8 million, while saying that most of CPR’s contents were stolen. It has not explained why roughly 3 million registry entries fall outside that affected count, whether all fields were taken for every affected entry, or what the unspecified additional information contains. A count of people, a count of database records, and a claim that “most” content was obtained are not interchangeable measurements.

OpenAI’s agent problem is now an enforcement problem

Recommended reading

OpenAI’s agent problem is now an enforcement problem

Sergey Kuznetsov • • 6 min read

DateWhat is established
September 2026Unauthorized access to CPR occurred
October 2, 2026The breach was discovered
October 5, 2026Denmark publicly confirmed the incident

The government believes this may be the largest data breach in Danish history. That assessment is based on the breadth of a national identity registry, not a large customer list from a single commercial service.

The failure was in authorized access

Attackers abused a Danish company’s lawful ability to search CPR information. Some companies are granted that capability to verify customer or citizen details against government records. The access itself was permitted; the collection of data through it was not.

The available account does not say whether the abuse involved compromised credentials, misuse by an insider, a weakness in the company’s own systems, insufficient controls around legitimate searches, or another route. It also does not disclose query-rate controls, export limits, audit logging, the time required to extract the material, or whether the company’s access has been disabled.

Without those details, containment cannot be meaningfully assessed. A national registry can restrict direct public access yet still be broadly exposed if trusted organizations can retrieve records at a scale that is difficult to distinguish from legitimate verification work. Denmark has established that a trusted access path was abused; it has not established how that path became a bulk-data channel.

A larger historical number needs context

Denmark’s breach has drawn comparison with a 2016 Turkish case involving an online database said to contain personal information for about 50 million citizens. The two events should not be treated as equivalent precedents. Denmark has confirmed an intrusion into CPR, while Turkish prosecutors opened an investigation into an alleged leak and Turkish officials disputed that the data came from the country’s central civil-registration system, MERNIS.

CaseReported scaleWhat authorities established
Denmark CPR breach, 2026About 8 million people affectedGovernment confirmed unauthorized access and theft of most CPR contents
Turkey alleged leak, 2016About 50 million citizens' recordsProsecutors investigated; officials disputed that MERNIS was the source

The Danish incident is also different from the up to 8.7 million customers affected in the Manchester Airports breach reported on August 29, 2026. That case involved contact, postcode, and vehicle data across airport services, with banking and financial information said to remain secure. CPR instead holds a government identity number used across public services. The two totals are similar; the systems and data roles are not.

Denmark has not said whether affected people will receive new identity numbers, whether it will alert every person with a compromised record, or whether it has found evidence that the stolen data has been published or used. It also has not named the company whose legitimate access was turned against CPR.

Frequently asked questions

What data was stolen from Denmark’s CPR system?+

The government says names, addresses, Danish social security numbers, and other unspecified information were stolen.

Who breached Denmark’s CPR database?+

Denmark has not identified the attackers or the Danish company whose lawful CPR access was abused.

When was the CPR breach discovered?+

The breach occurred in September 2026 and was discovered on October 2, 2026.

Sergey Kuznetsov

Editor-in-Chief

Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.

/ Keep reading