Denmark CPR Register Unauthorised Access Affects 8.8M
If you received a notice from Central Person Register (CPR), here’s what the filing says was exposed, and what to do about it.
The Danish Central Person Register (CPR) disclosed unauthorised access via misuse of a private company's legitimate query access, exposing names, addresses, and CPR numbers for approximately 8.8 million registered individuals (living, emigrated, deceased). The incident was detected on October 2 and publicly notified on October 5. Police and data authorities are investigating.
The Danish Central Person Register has confirmed that names, addresses, and CPR numbers belonging to 8.8 million people were accessed without authorisation through a private company’s legitimate query access. This means the core lifelong identifiers used across Danish public and private services are now in the hands of parties who should not have them.
Because legal names and CPR numbers cannot be changed, this exposure creates permanent risk. A CPR number combined with a name and address history functions as a master key for identity theft, benefit fraud, loan applications, and tracking of individuals across government and commercial databases. These records remain valuable to criminals for years.
Why CPR Numbers Matter More Than Most Data
A CPR number is the single most important personal identifier in Denmark. It links every official record you have — tax, healthcare, banking, voting, pensions, and housing. Once it is exposed alongside your name and address, anyone who obtains it can more easily impersonate you in systems that treat the CPR as proof of identity. Unlike a password or credit card, it cannot be replaced.
What the Filing Does and Does Not Reveal
The record states that the unauthorised access occurred through misuse of a private company’s approved connection to the CPR system. It does not describe a traditional technical hack of the CPR infrastructure itself, nor does it indicate that any passwords or login credentials were exposed. No password-related risk exists from this incident.
The Danish Ministry of Research, Education and Digitalisation disclosed the breach on 5 October 2026, two days after it was detected on 2 October. Police and data protection authorities are investigating the exact method and scale of misuse. The filing does not state how long the unauthorised queries ran before detection.
How to Determine Whether You Are Affected
The organisation is required to notify affected individuals directly, usually by post. If you have not received a letter, it is likely your records were not part of the exposed set. However, anyone who has moved since September 2026 should contact the Central Person Register directly to confirm whether their information was accessed.
What You Can Still Control
While the exposed identifiers cannot be altered, you can reduce the practical harm they enable. The most effective steps are these:
- Place a fraud alert or credit freeze with any credit reporting agencies or financial institutions you deal with. This forces lenders to verify your identity before opening new accounts in your name.
- Monitor your digital post (e-boks) and physical mail for unexpected applications, benefit claims, or address changes made in your name.
- Contact your bank and pension provider to request extra verification on any transactions or changes linked to your CPR number.
- Be extremely cautious with unsolicited requests that ask you to confirm your CPR number, even if they appear to come from official sources.
- Keep records of the notification letter and note the incident date of September 2026. This helps if you later need to dispute fraudulent activity tied to this breach.
The exposure of 8.8 million records represents nearly the entire Danish population. The fact that it occurred through authorised query access rather than a remote break-in raises serious questions about oversight of private companies given access to the CPR system. For individuals, however, the immediate reality is simpler: your permanent identifiers are now circulating beyond official control, and the letter in your postbox is the only reliable way to know if you are personally included.
Report details & sourcing
Related breaches
Malaysia National Registration Department 22.5 Million — May 2022
A breach of Malaysia's National Registration Department exposed ~22.5 million citizen records, inclu…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
149 Million Credential Mega-Exposure — January 2026
Security researchers discovered a publicly exposed 96 GB database with 149 million unique logins cov…