Security Guides
Denmark CPR register misuse (about 8.8 million people): what was taken, and what residents and organisations that grant lookup access should do
A private company's legitimate lookup access to Denmark's civil registration system (CPR) was misused to obtain names, addresses and CPR numbers of about 8.8 million people. Based on the Danish government's notice: what residents should do, and what organisations that grant lookup APIs should check.
For: people who live or have lived in Denmark and their families, and organisations that let outside businesses look up resident or customer data through an API or lookup screen. This article is based on the Danish government's official notice and does not cover attack techniques.
What residents (and former residents) should do today
Prepare as if you are affected
According to the ministry, about 8.8 million of the roughly 11 million registered people are affected, including emigrated and deceased persons. As of October 6, no way to check individually has been announced.
If you studied or worked in Denmark in the past, you may be affected if you were given a CPR number. Also watch for messages that use the name of a family member who has died.
Never share MitID details or one-time codes
The government security site sikkerdigital.dk asks people never to share MitID details, one-time codes, passwords or card details.
The ministry also reminds people not to give out passwords or similar by phone or email, even if the other person appears to know their name, address and CPR number. Those exact three items were taken, so a caller who knows them has proved nothing.
Do not tap links in texts or emails; go to the official site yourself
sikkerdigital.dk advises that if you receive an unexpected text or email with a link, you should not click it, and instead go to the official website yourself or call the sender's main number to double-check.
If someone calls you, hang up and call back on a number you looked up on the official site. The more a message rushes you, the more reason to doubt it (how to spot it: what is phishing).
If you suspect misuse, set a credit warning
According to sikkerdigital.dk, if you have a concrete suspicion that your CPR number is being used for fraud, you can set a credit warning (kreditadvarsel) on borger.dk. It is a marker in the CPR that makes it harder to take out loans or credit in your name.
According to borger.dk, you must be at least 15. The marker is registered in the CPR right away, but it can take a few days before it takes effect in companies' systems. It also makes borrowing harder for you, so you can remove it before applying for credit. If you cannot do it online, your municipality's citizen service can help (by appointment).
If you need help, call the Cyberhotline
The national Cyberhotline for digital security is +45 33 37 00 37. According to the ministry and sikkerdigital.dk, it is open 8 a.m. to midnight in the coming days.
If you reuse passwords across services, take this chance to separate them (how to check: how to check if your password was leaked; how to manage them: choosing a password manager).
What happened (from the Danish government's notice)
On October 5, 2026, Denmark's Ministry of Research, Education and Digitalisation published "Omfattende uautoriseret adgang til borgeres CPR-oplysninger" (extensive unauthorized access to citizens' CPR data). The same text is posted on the CPR's official website. Everything below is based on the ministry's notice.
During September 2026
There was irregular activity in the CPR system (the notice's fact box).Friday, October 2, evening
The CPR administration became aware of that activity.October 3–4 (weekend)
The administration learned that unauthorized persons had obtained names, addresses and CPR numbers of about 8.8 million people.October 5
The ministry announced the incident, and sikkerdigital.dk posted advice for residents. The minister says she informed the parliamentary committee.October 6
sikkerdigital.dk posted guidance for businesses and authorities that are contacted by citizens, asking them to review identity checks.
- Who
- About 8.8 million registered people, including living, emigrated and deceased persons
- Items
- Names, addresses, CPR numbers and more, within the data private companies are allowed to look up
- Not included
- Names and addresses of people registered with name and address protection (navne- og adressebeskyttelse)
- How
- Unauthorized persons misused a private Danish company's legitimate access to look up data in the CPR
- Company name
- Not disclosed in the notice
- Response
- The company's access was stopped; the Danish Data Protection Agency was notified; police are investigating with relevant authorities; measures to prevent similar incidents have started, and a thorough security review of the CPR is under way
- Open points
- The investigation is at an early stage and it is not known who is behind it. The ministry itself warns that further mapping may change the details
- Help
- sikkerdigital.dk, Cyberhotline +45 33 37 00 37 (8 a.m. to midnight for now)
Reported, but not in the ministry's notice
The Hacker News, a security news site, reports, citing the Danish news agency and the Data Protection Agency, that the lookups took place over about ten days in September and consisted of a very large number of automated lookups.
Neither point appears in the ministry's notice of October 5. This article does not treat them as established, and will be updated if the ministry publishes details.
Why private companies can look up the CPR at all
The ministry's notice includes a fact box on private companies' access. Under section 38 of the CPR Act, private companies with a legitimate interest may receive CPR data about people they have already identified one by one, using the CPR number, date of birth and name, or name and address.
In addition, the company must be entitled to receive the data under the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act. Section 38(2) of the CPR Act sets out which data such companies generally have access to.
In other words, what was used was not a back door but a lawful entrance granted to companies. Defences that stop intruders do not stop lookups that arrive with valid credentials.
A private company's account with lookup access
used by unauthorized persons
↓→
CPR lookup service
valid access, so sign-in succeeds
↓→
Results for about 8.8 million people
items private companies may look up
Where to notice: not at sign-in, but in how the access is used
per-client volume, deviation from normal, share of numbers not found, volume versus client size
What organisations that grant lookup APIs should check
This section is for organisations that let contracted businesses look up resident, customer or credit data through an API or lookup screen. Because the cause has not been disclosed, it covers points that apply to any service built this way.
How to design limits in general (who to count, what to count, what to do at the limit) is covered in rate limiting and abuse control. Signs of inhumanly fast activity, such as from AI agents, are covered in the DIVD case. Here we add what is specific to a legitimate client's access.
Give each client a limit that matches its declared customer base
Under the Danish rules, a company may look up people it has already identified one by one. So the number of people a client looks up in a month should not greatly exceed its number of customers.
As a first step, set daily and monthly lookup limits per client based on the customer count declared at contract time. Alert the account owner at 80% of the limit, and at the limit stop lookups and ask the client for the reason.
Watch deviation from normal and the share of numbers not found, daily
Absolute volume alone will not reveal anomalies at a client that is large to begin with. Use each client's average daily volume over the past 30 days as a baseline, and alert on days that exceed it several times over.
Another signal is the share of lookups that return no match. A client looking up its own customers should find almost all of them. A client whose not-found rate suddenly rises may be looking up people who are not its customers, so check with it at once.
Do not leave client account security to the client
When legitimate access is used by someone else, checking IDs and passwords does not help. Require, as a contract condition, multi-factor authentication, restrictions on source IP addresses, and regular rotation of API keys for lookup accounts (background: authentication vs. authorization, choosing two-factor authentication).
Also review once a year whether any client holds access that is unusually broad for its size, or access it no longer uses.
Record who looked up whom and when, and be able to cut access at once
For every lookup, record the client, the user, the time and the person looked up. A reasonable minimum retention is 12 months (the period the card industry standard PCI DSS requires for audit logs). Without these records you cannot answer whose data went out.
In this case the CPR administration stopped the company's access. For each client, decide the procedure and the person who can cut its access immediately without affecting other clients.
For businesses and authorities contacted by residents: review identity checks
On October 6, sikkerdigital.dk asked businesses and authorities that are contacted by citizens to reconsider whether name, address and CPR number are still enough if they have used them to verify callers. The methods it lists are below.
No longer proof of identity after this incident
- CPR number
- Name
- Address
- Date of birth
Checks listed by sikkerdigital.dk
- Ask the person to sign in to self-service, for example with MitID
- Send a one-time code to a phone number or email already on file
- Call back on a number already on file
- Ask about things specific to the relationship, such as a customer number or latest invoice number
The site says that for requests such as access to personal data, changes of contact details, new subscriptions, purchases on credit, new SIM cards, password resets or changes of payment details, strong verification should be used, and CPR number, name, address or date of birth should not be enough. It also suggests manual checks or a waiting period for changes with financial or security impact.
For readers in Japan: how My Number differs, and the lesson that still applies
According to Japan's Digital Agency, Japan's My Number is used for procedures set out in laws or ordinances, such as social security, tax and disaster response, and providing it for other purposes is in principle restricted. The agency also says that the number alone cannot be used to complete procedures (Digital Agency My Number FAQ, Japanese).
Despite the different systems, the lesson carries over directly: do not use numbers or addresses that many people can know as a password for identity. Businesses whose phone desks accept requests on name, address and date of birth alone should add a call-back to the number on file or a question specific to the relationship.
Sources (public record)
The facts in this article are based on the public information below. It does not cover the name of the company whose access was misused, who is behind the incident, or techniques that have not been disclosed.
- Danish Ministry of Research, Education and Digitalisation, "Omfattende uautoriseret adgang til borgeres CPR-oplysninger" (October 5, 2026, Danish) — ufm.dk
- CPR (Det Centrale Personregister), same notice (Danish) — cpr.dk
- sikkerdigital.dk, advice for citizens (October 5, 2026, Danish) — sikkerdigital.dk
- sikkerdigital.dk, guidance on verifying citizens for businesses and authorities (October 6, 2026, Danish) — sikkerdigital.dk
- borger.dk, "Kreditadvarsel" (Danish) — borger.dk
- Japan Digital Agency, My Number FAQ (Q1-4, Q1-7; Japanese) — digital.go.jp
- The Hacker News (October 2026, news report; its statements on the duration and method are not confirmed in the ministry's notice) — thehackernews.com
Update history
2026-10-06: First version, based on the Danish ministry's notice of October 5 and sikkerdigital.dk's guidance of October 5 and 6. The ministry says the investigation continues and details may change; this article will be updated when new facts are published.
Read next
- Designing lookup limits: Rate limiting and abuse control
- Government incidents in 2026: Government data breaches in 2026 and what citizens can do
- A leak from an ID application portal: France Titres (ANTS) data breach
- Preparing for impersonation: What is phishing / What is a one-time password
- Other incidents in 2026: List of data breaches and cyberattacks
FAQ
QWhat was taken in the Danish CPR incident?
According to the Danish ministry's notice of October 5, 2026, unauthorized persons gained access to names, addresses, CPR numbers and more for about 8.8 million registered people, including living, emigrated and deceased persons. The CPR holds about 11 million people. The data accessed stayed within the information that private companies are allowed to look up.
QWas the CPR system itself hacked?
According to the ministry, a private company's legitimate access to look up data in the CPR was misused. The CPR administration has stopped the company's access and is mapping the course of events with specialists and authorities. As of October 6, how that access came to be misused had not been disclosed.
QCan I check whether I am affected?
As of October 6, neither the ministry's notice nor the government security site sikkerdigital.dk describes a way to check individually. Since about four in five registered people are affected, anyone who lives or has lived in Denmark should prepare as if they are.
QWhich scams should I watch for?
sikkerdigital.dk asks people to be especially alert to texts, calls and emails in which the sender uses information about them. The ministry reminds people never to give out passwords or other confidential information by phone or email, even if the other person appears to know their name, address and CPR number. Never share MitID details, one-time codes, passwords or card details.
QShould I set a credit warning (kreditadvarsel)?
sikkerdigital.dk says that if you have a concrete suspicion that your CPR number is being used for fraud, you can set a credit warning on borger.dk. It is a marker in the CPR that makes it harder to take out loans or credit in your name. According to borger.dk, you must be at least 15, it can take a few days to reach companies' systems, and it also makes it harder for you to borrow yourself.
QIs the cause or the culprit known?
The ministry says the investigation is at an early stage and it is not yet possible to say who is behind it. The case has been reported to the Danish Data Protection Agency and is being investigated by the police. The ministry's notice does not name the company whose access was misused.