Nobody picked the lock. According to Danish authorities, someone used a key that had been handed out legitimately, and by the time anyone noticed, the names, addresses and CPR numbers of roughly 8.8 million people had been pulled from one of the most sensitive databases in the country.
Denmark’s Ministry of Research, Education and Digitalisation disclosed the incident on 5 October 2026. Investigators have not said who is behind it, and the ministry says it is too early to tell.
What the ministry says happened
The data came from the Central Person Register, known in Denmark as the CPR. Unauthorised parties obtained names, addresses and CPR numbers belonging to about 8.8 million registered persons, a group that includes people who are living, emigrated or deceased, according to the ministry’s own press release.
The register itself was not reported as breached. Instead, the access ran through a Danish private company that holds a lawful right to search the CPR. Under section 38 of the CPR Act, companies with a legitimate interest can receive data on a defined group of people they have already identified individually. What happened in September, the ministry indicates, went well beyond that purpose.
People who have name-and-address protection are not part of the exposed set, the ministry says. The company has not been named, and the ministry has not said how its access came to be misused.
A timeline that moved quickly once it started
The CPR administration became aware on the evening of Friday 2 October that irregular activity had taken place in the system during September. Over the weekend, staff worked out how large the problem was. By Monday, the ministry had gone public.
By then the administration had cut off the company’s access and reported the case to Datatilsynet, the Danish Data Protection Authority. Police are investigating, and the ministry describes that work as being at an early stage.
Some details come from a single chain of reporting, so they should be read with that in mind. The Hacker News, citing an interview Minister Christina Egelund gave to the Ritzau news agency, reported that the access lasted about ten days in September. The same outlet, relaying the Datatilsynet notice, described a very large number of automated lookups aimed at identifying valid CPR numbers.
How the activity was caught is also worth knowing. The Copenhagen Post, drawing on Ritzau, reported that an official attributed the detection to an unusually large invoice, since each search of the register carries a fee. If that account holds, the first alarm was a billing anomaly rather than a security tool. That detail has appeared in only one outlet so far.
Why a CPR number is not just another data point
To understand why this matters, it helps to know what a CPR number is. It is a lifelong national identifier that follows a person through tax, healthcare and banking, as Help Net Security noted in its coverage. A leaked password can be changed. A leaked CPR number cannot.
That is the heart of the risk. A name, an address and a CPR number together are exactly what a fraudster needs to sound credible on the phone or in an email. The ministry itself has warned that scammers may get in touch and still appear to know the person’s name, address and CPR number, which means that familiarity alone should not be read as proof of legitimacy.
Its public guidance is simple. Never share passwords or confidential details by phone or email. More advice is available on the government’s Sikker Digital site, which the ministry directs citizens to. A cyber helpline is also open from 8:00 to 24:00 on +45 33 37 00 37, according to the press release.
Why the number is larger than Denmark’s population
The headline figure can look strange at first. The CPR has recorded everyone who has lived in Denmark since 1968, the year the register’s administration was established, so it holds far more entries than there are people in the country today. The ministry puts the total at about 11 million people, which makes the 8.8 million affected roughly four in five records.
That scale is part of what makes the case notable. Taken together with the ministry’s account of how it happened, the breach shows how a state register can be drained through an authorised third party rather than a direct attack on the system. The weak point was not necessarily the database. It was the trust placed in everyone with permission to query it.
The ministry has also cautioned that further mapping of the incident could change the details, so the 8.8 million figure is described as approximate and not final.
What the minister has said
Egelund called the episode “Det er en dybt alvorlig hændelse,” which translates roughly as “a deeply serious incident.” She has briefed parliament’s Business and Digitalisation Committee and asked for a thorough security review of the CPR system. She also said steps to prevent similar incidents have already begun.
No completion date for the review has been published. The ministry says its findings will form the basis for any further measures, so the real policy response is still to come.
What to watch next
Several of the most important questions remain open, and the ministry has not confirmed dates for answers to any of them. Investigators have not said who is behind the activity, how the company’s access was compromised, or whether the data was retained or used. It is also unclear whether individuals will be notified and whether the company will ultimately be named.
Datatilsynet, for its part, is examining what happened and who bears responsibility for the data processing, as The Hacker News reported. Its findings will matter beyond this one case, because the central question is where responsibility sits when a lawful access right is misused.
For Denmark, the coming weeks will show whether the security review stays confined to one company’s access or widens into a harder look at everyone who is allowed to search the register. For anyone whose details are in that 8.8 million, the practical consequences may unfold more slowly than the news cycle, since a CPR number, once exposed, stays exposed for life.






