8.8 Million CPR-numre Exposed in Security Breach
Personal data, including CPR-numre, for approximately 8.8 million people was accessed by unauthorized parties via a Danish company's system.
Quick facts
- 8.8 million CPR-numre, names, and addresses were accessed.
- The breach occurred through a private Danish company's authorized system access.
- The incident took place during September 2026.
Why it matters
This incident represents a significant challenge to Denmark's centralized digital infrastructure, where the CPR-nummer acts as a primary identifier for nearly all public and private services. The reliance on third-party access points for sensitive government databases raises questions about the security standards applied to private sector partners. The full extent of the potential misuse of this data remains under investigation by police and data authorities.
A severe security incident has affected the Central Person Register (CPR), resulting in unauthorized access to the personal data of approximately 8.8 million people. According to the Ministry of Higher Education and Science, the compromised information includes names, addresses, and CPR-numre.
How did the breach happen?
The unauthorized access was achieved by exploiting a private Danish company's legitimate access to the CPR system. The breach occurred during the month of September 2026, according to the CPR administration. The system, which contains data on roughly 11 million registered individuals, has since had the affected company's access revoked.
What are the authorities doing?
Minister for Higher Education and Science Christina Egelund has confirmed that the incident has been reported to the Data Protection Agency (Datatilsynet) and the matter is currently under police investigation. The government has initiated a thorough security review of the CPR system to prevent similar events in the future. Officials noted that individuals with registered name and address protection were not included in the compromised data.
What should citizens do now?
The Ministry advises all citizens to remain vigilant regarding their personal information. The official recommendation is to monitor the website sikkerdigital.dk for updates and guidance on digital safety. Authorities emphasize that citizens should never share passwords or other confidential details in response to unsolicited requests.
Frequently asked questions
What happened to the CPR-numre?
Unauthorized parties gained access to names, addresses, and CPR-numre for approximately 8.8 million people. This occurred by misusing a private Danish company's legal access to the CPR system during September 2026.
Is my data safe if I have name and address protection?
According to the authorities, the unauthorized access did not include names and addresses of individuals who have formally registered for name and address protection in the CPR system.
Who is behind the attack?
The identity of the parties responsible for the unauthorized access is currently unknown. The CPR administration and relevant authorities are investigating the incident, but details about the perpetrators were not available at the time of writing.
What should I do if I am worried about my CPR-nummer?
The Ministry of Higher Education and Science urges citizens to be vigilant. You should visit the official website sikkerdigital.dk for current advice on how to protect your personal information and stay informed about the situation.
Has the vulnerability been fixed?
The CPR administration has terminated the specific company's access to the system. Additionally, the government has launched a thorough security review of the CPR system and initiated new measures to prevent similar breaches in the future.
How many people are registered in the CPR system?
The CPR system currently holds records for approximately 11 million people, including living residents, those who have moved abroad, and deceased individuals.
In this story
Sources
Last checked Oct 5, 2026 at 1:15 PM. Trends move fast, so details may change. How we work
Comments