Skip to content

Technology·News & analysis

Denmark's national ID register breached, exposing 8.8 million people's CPR numbers

Unknown attackers abused a private company's legal access to Denmark's Central Person Register to pull names, addresses and CPR numbers for about 8.8 million people.

By Dan Kost aka Poseidan7 min read
Christiansborg Palace in Copenhagen, home of the Danish parliament, lit up at dusk and seen through the arched gate pavilions of the Marble Bridge
Photo: Moahim / Wikimedia Commons, CC BY-SA 4.0

Tide

Wave

Sci-fi

1/10

Reality

Shipping

No hacker broke the door. Someone just borrowed a company's key.How we rate

The Squeeze

Denmark says attackers took names, addresses and CPR numbers for about 8.8 million people from its central population register by abusing a private company's legal access.

The CPR number is used everywhere in Danish life, from tax to banks to healthcare. Officials say the data could make scam calls and emails far more convincing, so Danes are being told to stay alert.

What to know

  1. Unauthorized people got names, addresses and CPR numbers for about 8.8 million people in Denmark's Central Person Register, the government says.
  2. They didn't break into the system directly. They abused a private Danish company's legal access to search the register, using a huge number of automated lookups.
  3. The searches happened during September and were spotted on October 2. Police are investigating, and it's not yet known who is behind it.
  4. People registered with name and address protection were not exposed. Officials warn Danes to watch for scam calls, texts and emails.

Denmark has suffered what may be the biggest data breach in its history. Unknown attackers got hold of names, addresses and personal ID numbers for about 8.8 million people in the country's central population register, the Danish government said on Monday.

"It is a deeply serious incident," said Christina Egelund, Denmark's minister for higher education, science and digitalization.

What happened?

The breach hit the Central Person Register, known as the CPR. It's the database behind the CPR number every Danish resident gets.

What was taken: names, addresses, CPR numbers and other details for about 8.8 million registered people, according to the CPR administration. That includes people who are living, people who have moved abroad and people who have died.

Who was spared: people who chose to register with name and address protection weren't exposed, the CPR administration says.

TechCrunch, which initially reported the figure as some 8 million, says this is thought to be the biggest data breach in the country's history.

How did the attackers get in?

They didn't break into the system directly. Instead, they abused a private Danish company's legal access to search the register, according to the government.

Some Danish companies are allowed to look up information in the CPR. Under section 38 of the CPR law, private companies with a legitimate interest can get data about people they've already identified, for example by CPR number, birth date and name, or name and address, the ministry says.

Automated lookups: the Danish Data Protection Agency, Datatilsynet, says a very large number of automated lookups were made against the CPR system to identify valid CPR numbers.

The government hasn't named the company. Its access has been shut off, and the CPR administration is working with specialists and other authorities to map out what happened.

The Copenhagen Post reports Egelund said security around the company's access was inadequate.

When did it happen?

  • September: the unauthorized searches took place throughout the month.
  • Friday, October 2: the CPR administration noticed irregular activity in the system, according to the ministry.
  • Weekend of October 3-4: officials established that data on about 8.8 million people had been accessed.
  • Sunday, October 4: the CPR register reported the incident to Datatilsynet.
  • Monday, October 5: the government went public.

Why is the CPR number such a big deal?

The CPR system is a cornerstone of Denmark's highly digitized public sector, Bloomberg reports, as carried by Insurance Journal.

Every resident is assigned a unique 10-digit CPR number. It's widely used to identify people when dealing with government agencies, banks and healthcare providers, and for paying tax, TechCrunch notes.

More records than people: Denmark has a population of about 6 million, but the register holds records on about 11 million people, including those who have died or moved abroad. Some of the data goes back decades, according to TechCrunch.

Who is behind it?

Nobody knows yet. "The investigation is at an early stage," the ministry says, and it's not currently possible to say who is behind the unauthorized access.

Police are investigating together with the relevant authorities. Datatilsynet says it's looking at what happened, how it could happen, and who is responsible for handling the personal data involved.

What is the government doing?

Egelund says she has briefed the Danish parliament's Business and Digitalization Committee.

  • Access cut off: the company's access to the CPR has been stopped.
  • New safeguards: the government says it has already started measures to prevent similar incidents.
  • Security review: Egelund has ordered a thorough security review of the entire CPR system, which may lead to further changes.
  • Extra help: the Cyberhotline for digital security on +45 33 37 00 37 has extended its hours to 8 a.m. to midnight in the coming days.

How could the data be misused?

The main danger is more convincing scams, not instant access to your money.

A CPR number alone doesn't give access to online banking or MitID, Denmark's digital ID, according to the senior citizens' group Faglige Seniorer, citing the government site Sikkerdigital. But scammers can use your real name, address and CPR number to make a fake call, text or email sound genuine.

Faglige Seniorer notes that there's no documented evidence yet that this particular data has been used for fraud.

The government's warning: never give out passwords or other confidential information in phone calls or emails, "even if the recipient apparently knows your name, address and CPR number," the ministry says.

What scams should people watch for?

Faglige Seniorer, Denmark's second-largest organization for older people, has listed 17 ways real names, addresses and CPR numbers could make a scam more believable. It stresses that these are possible scenarios, not documented consequences of this breach. Among them:

  • Fake bank call: a caller who knows your details claims your account is at risk after the CPR incident and asks you to move your savings to a "safe account" that actually belongs to the scammer.
  • Fake bank courier: you're told the bank will send someone to collect a compromised card. The courier takes your card and PIN.
  • Fake police officer: someone claims your valuables at home are in danger and need to be collected for safekeeping.
  • "Your MitID must be secured" texts: a personal-looking text sends you to a fake page to collect details or get you to approve something.
  • Fake credit-warning emails: scammers copy the official advice to set up a credit warning and send you to a fake version of borger.dk.
  • Fake pension or refund messages: someone posing as a pension provider or promising money back asks for card details or a MitID approval.
  • Paid "protection": a person or company offers to "block your CPR number" or remove your data from the internet for a fee.
  • Recovery scams: after a loss, a fake adviser offers to get your money back for an upfront fee.

Some kinds of identity fraud, such as taking out loans or redirecting public payments to another account, usually need more than a name, address and CPR number, the group notes.

Has this happened elsewhere?

Yes. National ID databases have been hit before, TechCrunch notes. It points to a 2016 breach affecting millions of Turkish citizens and several exposures of data from India's national Aadhaar database.

What it means for you

If you live in Denmark, or ever did:

  • Treat callers with suspicion: someone knowing your CPR number proves nothing. Hang up and call your bank or the authority back on its official number.
  • Never share codes: don't give out MitID approvals, one-time codes, passwords or card details, no matter who asks.
  • Set a credit warning: you can add one on borger.dk, which makes it harder for others to take out loans in your name, Recordere notes.
  • Don't click unexpected links: go to the official website yourself, or call the sender's main number to check whether a message is real, Recordere advises.
  • Get help: visit sikkerdigital.dk or call the Cyberhotline on +45 33 37 00 37.

The bottom line

Attackers used a private company's legal access to Denmark's CPR register to collect names, addresses and ID numbers for about 8.8 million people. It's not yet known who did it, and police are investigating. For now, the biggest risk for Danes is scammers armed with real personal details, so a healthy dose of suspicion is the best defense.

Key facts

People affected
About 8.8 million, including the living, emigrants and the dead
Data taken
Names, addresses, CPR numbers and more
How
Misuse of a private company's legal access to search the CPR
When
During September; spotted October 2, 2026
Who's behind it
Not yet known; police are investigating

Got questions?

Quick answers, plain words

What happened?

Unauthorized people got access to names, addresses, CPR numbers and other details for about 8.8 million people registered in Denmark's Central Person Register (CPR), the Danish government said on Monday.

What is the CPR?

It's Denmark's central population register. Every resident gets a unique 10-digit CPR number used with government agencies, banks and healthcare providers. The register holds about 11 million people, including those who have died or moved abroad.

How did the attackers get in?

They misused a private Danish company's legal access to search the register. The Danish Data Protection Agency says a very large number of automated lookups were made to find valid CPR numbers.

Which company was it?

The government hasn't named it. Its access has been shut off.

Who is behind the breach?

It's not known yet. The investigation is at an early stage, and police are working with the relevant authorities.

Was everyone affected?

No. People who chose to register with name and address protection weren't exposed, according to the CPR administration.

Can someone get into my bank with my CPR number?

Not on its own. A CPR number alone doesn't give access to online banking or MitID, Faglige Seniorer notes, citing Sikkerdigital. The bigger risk is scammers using your real details to sound trustworthy.

What should Danes do now?

Never give out passwords, codes or MitID approvals over the phone or email, even if the caller knows your name, address and CPR number. You can also set a credit warning on borger.dk, and get help at sikkerdigital.dk or the Cyberhotline on +45 33 37 00 37.

Is this the biggest breach in Denmark?

TechCrunch reports it's thought to be the biggest in the country's history.

SourcesDanish Ministry of Higher Education and Science
Topics and tagsCybersecurity, denmark, data breach, cybersecurity

The daily newsletter

Tech news you'll actually get.

One short email a day. Five minutes. Plain words. The daily email is launching soon. Join the early list.

Free. Early list: we'll email you when the first issue goes out.

More in brief