Denmark CPR data breach: 8.8 million records exposed
The Denmark CPR data breach, confirmed by the ministry, reached 8.8 million names, addresses and ID numbers. How it happened, who is covered and what to watch.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

The Denmark CPR data breach is confirmed: unauthorized people got hold of the names, addresses and CPR numbers of about 8.8 million people in the country's central person register by misusing a Danish company's legitimate access to search it. The ministry in charge announced it on October 5, 2026, police are investigating, and the minister says the security around that company's access "has not been good enough." Here is what leaked, who is and isn't affected, and what to watch for if you live in Denmark or ever did.
Key takeaways
- 8.8 million records: the ministry says the access covered names, addresses and CPR numbers of about 8.8 million registered people, living, deceased and emigrated, out of roughly 11 million in the register.
- No hack of the register itself has been reported: the access came through a private Danish company's lawful lookup rights. The company has not been named, and the access has been cut off.
- Protected addresses were left out: people registered with name and address protection did not have their names and addresses included, according to the ministry's review so far.
- Phishing is the main risk: authorities ask you never to give out passwords or MitID codes, even when a caller or email already knows your name, address and CPR number.
- Who did it is unknown: the ministry says the police investigation is at an early stage.
What happened in the Denmark CPR data breach
The CPR (Det Centrale Personregister) is Denmark's national register of people, and the CPR number is the personal ID Danes use for health care, banking, taxes and almost everything else. According to the ministry's press release (in Danish; quotes here are our translation), the CPR administration noticed "irregular behavior" in the system on the evening of Friday, October 2, and over the weekend established that someone had obtained names, addresses and CPR numbers of about 8.8 million registered people.
That number is larger than Denmark's population of roughly 6 million because the register also keeps records of people who have died or moved abroad. The ministry puts the register's total at about 11 million people. Digitalization Minister Christina Egelund told reporters the access ran for about 10 days in September, as the Copenhagen Post reports.
How a company's lookup access was misused
Private companies in Denmark can get data from the CPR when they have a legitimate interest, under section 38 of the CPR Act, for people they have already identified. The ministry says the attackers used one such company's lawful search access, "within the scope of the information private companies have access to." In other words, nothing published so far points to a software flaw in the register; the queries looked like the company's own.
Egelund has not named the company. The Copenhagen Post reports she called it a small Danish company and said that warning systems should have reacted sooner. The ministry has also not said how the attackers got control of the company's access.
Who is affected, and who isn't
If you have a CPR number, assume you may be in the 8.8 million. That includes people who once lived in Denmark and moved away, since the ministry counts emigrated people in the total.
The ministry's review found that the names and addresses of people registered with name and address protection were not included. It cautions that its figures are preliminary and may be refined as the investigation goes on.

What to watch for: phishing that knows your details
A CPR number begins with your date of birth, so the leak effectively hands out birth dates too. Cybersecurity professor Jens Myrup Pedersen told DR it is the biggest breach ever against the Danish CPR register, and that this kind of data is very effective for phishing and identity theft. In a second Copenhagen Post piece, he says it should not be enough on its own to take out a loan in your name, because lenders cannot treat knowing a CPR number as proof of identity.
The government's security site, Sikker Digital, lists four steps:
- Be extra careful with unexpected contact: texts, calls and emails that mention your personal details.
- Don't click unexpected links. Go to the official site yourself or call a number you already trust.
- Never share your MitID details, one-time codes, passwords or card numbers.
- Set up a credit alert (kreditadvarsel) on borger.dk, which makes it harder to borrow money in your name.
The Cyberhotline for digital security, +45 33 37 00 37, has extended its hours to 8:00 until midnight in the coming days. Fake messages often lean on familiar brands, as in the fake ChatGPT malware trap we covered last week.
What the government has admitted
Egelund called it "a deeply serious incident" in the ministry's release and said she had briefed the Danish parliament's business and digitalization committee. She has asked for a thorough security review of the CPR system, and the ministry says measures to prevent a repeat are already in place, without saying what they are. Her sharper admission came to the press: "It is clear to me that the security measures surrounding this company's access to CPR have not been good enough," she said, according to the Copenhagen Post.
The CPR administration has reported the incident to Datatilsynet, the Danish data protection authority. DR reports that the National Unit for Special Crime (NSK) has opened an investigation it calls a high priority. Nobody has said who is behind it.
A separate university breach
Not every Denmark data breach in the news this week is the same one. On October 2, the Technical University of Denmark disclosed its own breach, and it is a different incident. Attackers used compromised DTU accounts to reach the university's identity system and download a large amount of data on up to 200,000 current and former staff, students and guests, including CPR numbers. DTU has not linked it to the CPR register breach. It is notifying people through e-Boks.
The week's other urgent security story is for IT teams, not citizens: the NetScaler SAML zero-day that last week's Citrix patch does not fix.
Bottom line
In the Denmark CPR data breach, the ministry has confirmed that about 8.8 million records were reached through one company's legitimate lookup access, and the minister admits the controls around it were not good enough. For you, the practical defense is skepticism: treat any message that quotes your details as a reason for caution, never share MitID codes, and set up a credit alert. Watch for the security review's findings and for police to say who was behind it.
FAQ
What data was taken in the Denmark CPR breach?
The ministry says names, addresses and CPR numbers of about 8.8 million registered people. Because a CPR number starts with the date of birth, birth dates are exposed as well. People registered with name and address protection did not have their names and addresses included.
Why is the number higher than Denmark's population?
The register keeps records of people who have died or moved abroad, about 11 million in total. The 8.8 million figure counts living residents, emigrants and deceased people together.
Do I need to do anything?
Authorities ask you to be wary of unexpected calls, texts and emails, never to share MitID codes or passwords, and to consider a credit alert on borger.dk. Sikker Digital and the Cyberhotline, +45 33 37 00 37, can help.