Attackers used a firm's access to take 8.8 million Danish CPR records
EditorialBy TrustList Editorial
The data covers living, emigrated and dead people, about 80% of the register. Datatilsynet received the breach notification on 4 October and has not yet said who is responsible.
- Denmark
- Cybersecurity
- Data Security
- GDPR Compliance
About Attackers used a firm's access to take 8.8 million Danish CPR records
Attackers used a firm's access to take 8.8 million Danish CPR records
5 October 2026: Danish authorities say attackers misused a private company's legitimate access to the Central Population Register (CPR) to collect names, addresses and CPR numbers for about 8.8 million people. That is roughly 80% of the 11 million records in the system, and it includes people who live in Denmark, people who have emigrated and people who have died.
The ministry responsible says the incident happened in September. According to BleepingComputer's account, the register's administration learned of it on 2 October and worked out the scale over the following weekend. The company's access has been blocked, police are investigating together with the relevant authorities, and a security review of the whole CPR system is under way. People who are registered under name and address protection are not among those whose data was taken, the ministry says.
The Danish Data Protection Agency, Datatilsynet, received the register's breach notification on Sunday 4 October. It describes a very large number of automated lookups made to identify valid CPR numbers, and says it is still examining what happened, how it was possible and who is responsible for the processing of the personal data. It has said it will comment further when there are grounds to do so.
Minister Christina Egelund has called the incident extremely serious and informed the parliamentary committee for business and digitalisation. The cyber hotline for people who may be affected now runs from 8am to midnight, and guidance is published on sikkerdigital.dk. The ministry warns citizens that a caller or email that knows their name, address and CPR number is not for that reason genuine, and that passwords and other confidential details must never be given out in reply.
The announcement does not name the company or say how its access was obtained. BleepingComputer's request for those details had not been answered when it published.
Sources
- Danish Ministry of Research, Education and Digitalisation: extensive unauthorised access to citizens' CPR data, 5 October 2026
- Datatilsynet: the agency is aware of a case concerning lookups in the CPR (read 2026-10-06), 6 October 2026
- BleepingComputer: Denmark population registry data breach affects 8.8 million people, 5 October 2026
Categories & features
- Denmark
- Cybersecurity
- Data Security
- GDPR Compliance
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More DenmarkThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.