Connect with us

NEWS

Denmark’s Company Search Rights Opened 8.8 Million CPR Records

Unauthorized parties used a Danish firm’s legal CPR search rights to reach about 8.8 million names, addresses and ID numbers, prompting a full register review.

Published

on

Unauthorized parties used a Danish company’s lawful search rights to reach names, addresses and personal ID numbers for about 8.8 million people in the Central Person Register. The Ministry of Research, Education and Digitalisation said the access took place in September 2026 and was noticed on the evening of 2 October.

The path was a private firm’s legal right to query the register, a channel Danish law already gives to banks, utilities and other businesses that need to keep customer files current.

A Small Firm’s Lawful Login Opened 8.8 Million Records

The CPR administration found access to about 8.8 million registered people, including residents, people who have left Denmark and people who have died. The haul covered names, addresses, CPR numbers (Denmark’s personal ID used for tax, health and banking) and other fields that private firms are allowed to see.

Christina Egelund, the minister for digitalisation, said the traffic ran for about 10 days in September through a small Danish company that had a legal login. The company has not been named. Its access has been cut. Police are investigating with the National Unit for Special Crime, and the case has been filed with Datatilsynet, the data protection authority.

People who had registered name and address protection were left out of that name-and-address slice. Egelund called the episode deeply serious, told parliament’s Business and Digitalisation Committee, and asked for a full security review of the CPR system.

THE SEPTEMBER ACCESS WINDOW

  1. September 2026: Unauthorized parties use a private Danish company’s lawful CPR search access for about 10 days, the minister said.
  2. 2 October 2026: The CPR administration notices irregular behaviour in the system on Friday evening.
  3. 3-4 October 2026: Over the weekend the administration maps the scale at about 8.8 million registered people.
  4. 4 October 2026: The register notifies Datatilsynet.
  5. 5 October 2026: The ministry makes the incident public and says the company’s access has already been stopped.

A search right that can run at that volume for about 10 days without a hard stop is a monitoring failure sitting on top of a vendor failure. Egelund said the safeguards around this firm’s access were not good enough, and that warning lights should have come on given how long it lasted.

The Lookup Right Under Section 38

Private companies with a legitimate interest may, under section 38 of the CPR Act, receive defined data on a larger group of people they have already identified one by one, by CPR number, by date of birth and name, or by name and address. They also have to be allowed to process that data under the GDPR and the Danish Data Protection Act.

In daily use this is the person subscription. A bank, a utility or a credit watcher keeps a live feed on its own customers so a move, a death or a name change shows up the same evening. CPR’s own guidance lists what private firms may receive from CPR, and it is a short list.

Field Private companies under section 38
Current name Yes, unless name protection is registered
Current address and date of move Yes, unless address protection is registered
Job title, death, disappearance, emigration, guardianship, contact address Yes, when those events are on file
CPR number as a new field Not released; a firm sends a number it already holds, and the number can be sent back only to confirm the match
Church membership Not in the private-company feed

The same CPR pages name the bureaus that show up on many citizens’ subscription lists because they run data for someone else, among them Experian Servicebureau, KMD and Netcompany Banking Services. None of those firms has been tied to this incident. The ministry has only said the abused login belonged to a small unnamed Danish company.

Anyone with MitID can see which authorities and companies subscribe to their record through the register-insight service on borger.dk. After the 5 October announcement that page slowed under traffic. The Agency for Digital Government confirmed delays. A deputy director there said people should expect they are probably covered, because about 8.8 million of about 11 million records were reached.

What Were the Automated Lookups Searching For?

Datatilsynet said the register’s notice described a very large number of automated lookups to identify valid CPR numbers. The authority received that filing on 4 October and has not yet judged the facts. It used the word allegedly for the retrieval itself.

That detail sits next to the subscription rule in an awkward way. The legal safeguard is supposed to sit on the input side: a company may only ask about people it has already identified. If the channel also answers, at machine speed, whether a guessed number exists, the safeguard becomes a yes-or-no machine for the entire national ID space.

The ministry said the unauthorized access stayed inside the categories of data private companies are allowed to receive. Scale, not a secret field, is the break. Jens Myrup Pedersen, professor of cybersecurity at Aarhus University, called it the largest breach ever against the Danish CPR register, and said a login should not see more than it needs, with alarms when the query volume goes strange.

How the outsiders got the company’s access, a stolen password, a weak system, or someone on the inside, has not been disclosed. Egelund said no trail is off the table, including an international one.

About Four in Five Register Records Were Reached

Denmark’s living population is about 6 million. The register is larger because it keeps the dead and people who moved away, which is why about 8.8 million records can be touched in a country that size. About four in five of the roughly 11 million entries were reached.

THE SCALE OF THE CPR FILE

  • Register size: About 11 million records, including residents, emigrants and deceased people.
  • Access window: About 10 days in September 2026, according to Egelund.
  • Protection carve-out: Name and address protection kept those people’s names and addresses out of the accessed set.
  • Citizen line: Cyberhotline 33 37 00 37, hours stretched to 08:00-24:00 in the days after the announcement.

A CPR number plus a name and a home address is not MitID. It is enough for a phone call that sounds like the tax agency, a bank or the municipality. The ministry’s own warning is that you should not hand over passwords or other secrets just because the caller already knows those three facts.

Users of the Danish Immigration Service and the Agency for International Recruitment and Integration were told they may also be affected. Both bodies added extra checks on Immigration Service calls before staff will help.

Egelund Orders a Full Security Review

In the ministry statement of 5 October, Egelund put the blame in public language that did not wait for a finished police file.

It is a deeply serious incident, which is why I have also briefed the Folketing’s Business and Digitalisation Committee. Together with all relevant authorities, we are mapping the full extent of the incident. We have already launched initiatives in relation to CPR to prevent similar incidents. I have also asked for a thorough security review of the CPR system.

Christina Egelund, Minister for Research, Education and Digitalisation, 5 October 2026 statement

She later said it was too early to know whether some people will need a new CPR number, and she did not rule that out. Nicklas Fallesen, acting deputy police inspector at the National Unit for Special Crime, said the unit had opened a high-priority investigation. Datatilsynet said it is looking at what happened, how it could happen, and who is responsible for the processing.

WHAT WE KNOW

  • The count: About 8.8 million registered people, from a file of about 11 million.
  • The path: A private Danish company’s lawful search access, now cut off.
  • The method described: A very large number of automated lookups aimed at valid CPR numbers, per the register’s notice to Datatilsynet.
  • The carve-out: Names and addresses under protection were not in the unauthorized access.

WHAT IS UNCONFIRMED

  • The actor: No one has been named, and the ministry says it cannot yet say who is behind the access.
  • The company: Still unnamed; only described as small and Danish.
  • The copy: Authorities have not said how much was taken off the system, as opposed to looked up inside it.
  • The remedy: New CPR numbers are not decided, and the extra CPR safeguards have not been spelled out.

Those blanks are why a mass reissue of numbers would be a political choice still sitting on the table, not a technical fact. Replacing an ID that is baked into tax, health, banking and MitID would be a national project. Leaving the numbers in place leaves the phishing window open.

5.28 Million Numbers on Two Unencrypted CDs

Pedersen, looking for earlier cracks in the same register, pointed back to 2015. That case was not a login. It was a parcel.

On 18 February 2015, Statistics Denmark told Datatilsynet that a registered shipment from Statens Serum Institut, meant for Statistics Denmark, had been delivered by mistake to the Chinese Visa Application Centre in Copenhagen. Inside were two unencrypted CDs. Datatilsynet’s later decision put the count at 5,282,616 people who had lived in Danish municipalities between 2010 and 2012. The discs held personal ID numbers and extracts from health registers. They did not hold names and addresses.

The visa office, a private firm that helps with China visa paperwork, said a staff member opened the envelope, saw CDs instead of a passport, and walked the packet to the right recipient in the same building. Datatilsynet criticised the lack of encryption. It is a smaller file than this one, and a different kind of failure, a misdelivered disc rather than a live search account. Both times, CPR data left through a channel that was supposed to be trusted.

Keep Your MitID Away From Callers

The Agency for Societal Security and the ministry pointed people to Sikkerdigital for official guidance after the CPR leak. The advice is blunt because the data now in unknown hands is exactly the bait used in voice and mail fraud.

WHAT AUTHORITIES TELL CITIZENS TO DO

  • Unexpected contact: Treat SMS messages, calls and emails that use your name, address or CPR number as hostile until you have checked them through an official site or a listed main number.
  • Links: Do not click unexpected links; open the real site yourself or call the organisation’s published number.
  • Secrets: Never share MitID details, one-time codes, passwords or card data, even when the other party already knows your CPR number.
  • Credit warning: If you suspect fraud with your number, set a credit warning on borger.dk, a flag in CPR that makes it harder to take loans in your name.

Help with that flag, and with identity misuse, sits with the Cyberhotline for digital security on 33 37 00 37. The ministry said the line would run from 08:00 to 24:00 in the days after 5 October. Its ordinary hours are 08:00 to 20:00 on weekdays.

Other companies still hold the same class of login the unnamed firm used. The review Egelund ordered is supposed to say whether those logins need rate limits, faster kill switches, or a narrower reading of section 38. Until that work is done, the register that makes Danish digital life simple remains reachable through every firm the state has already let in.

Harry is the editor of WORLDHAB, an independent publication that he owns and edits himself. His decade in journalism started in reporting and moved into editing, and it left him with a short list of promises that readers can expect every article here to keep. Sources are named and linked, so a claim about a company, a government or a team can be traced to the statement, filing or transcript it came from. Dates are given in full, figures are checked against the original table before publication, and where a number is an estimate the story says whose estimate it is. Headlines describe what happened rather than tease it. Those expectations hold across all ten sections WORLDHAB publishes for an international audience: news, business, technology and science on one side, sports, entertainment, lifestyle and travel on another, with auto and gaming covered with the same seriousness. Harry keeps a public corrections policy and marks every change on the article it affects. Reader mail is read by him and answered from support@worldhab.com.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending