
Unauthorised parties were reportedly able to access names, addresses and CPR numbers linked to about 8.8 million people registered in Denmark's Central Person Register, or CPR, by misusing a private Danish company's lawful access to the system.
The CPR administration detected irregular activity on the evening of Friday, 2 October. The Danish government disclosed the security incident on Monday, 5 October, as police and other authorities continued investigating how the company's access was misused.
The affected information relates to about 8.8 million of the roughly 11 million people registered in the CPR system. That total includes current residents, people who have moved abroad and people who have died.
Authorities have not identified those responsible. They have also not publicly explained how the unauthorised parties gained control of or otherwise misused the company's access.
How the Company's CPR Access Was Misused
Danish authorities have not said that the central CPR database itself was directly breached.
Instead, unauthorised parties used access that had legitimately been granted to a private Danish company to search information in the CPR system. The access remained within the categories of information that private companies were permitted to obtain.
The company has not been publicly identified. The CPR administration stopped its access after discovering the incident, while police and other relevant authorities began investigating.
The Danish government said the unauthorised access covered names, addresses, CPR numbers and other information available within the limits of the company's permitted access. Authorities have not publicly detailed every category of information obtained.
A government review found that the unauthorised access did not include the names and addresses of people registered with name-and-address protection. The finding does not establish that every other type of CPR information concerning those people was necessarily outside the scope of the incident.
Misuse Continued for About 10 Days
Digitalisation Minister Christina Egelund told Danish news agency Ritzau that the misuse continued for roughly 10 days during September.
According to Egelund, a CPR administration employee detected unusual activity on Friday, 2 October. By Saturday, authorities had developed a clearer picture that they were dealing with a serious security incident.
Egelund said the security measures surrounding the company's CPR access had not been strong enough. She also acknowledged that warning signs should have been triggered sooner given how long the activity continued.
The company's access was subsequently closed. Authorities are still investigating how the unauthorised parties were able to misuse it.
Regulator Says Searches Were Automated
Denmark's Data Protection Agency, Datatilsynet, received a breach notification from the CPR register on Sunday, 4 October.
According to the regulator, the notification said a very large number of automated searches had been made against the CPR system with the aim of identifying valid CPR numbers.
Datatilsynet is examining what happened, how the searches were possible and who was responsible for processing the personal data involved.
The regulator said the case remains under investigation and that it is not yet in a position to assess the specific circumstances. Police have also not publicly identified those responsible.
What the Incident Means for Danes
The accessed information could make phishing and other fraud attempts more convincing. Danish authorities have warned people to be particularly cautious about unexpected calls, emails and text messages in which the sender appears to know personal information about them.
MitID says a CPR number cannot itself be used as a MitID user ID. Cybersecurity professor Jens Myrup Pedersen of Aarhus University also told Ritzau that names, addresses and CPR numbers should not, by themselves, be enough to take out a loan in another person's name.
Pedersen warned, however, that the information could help criminals create more convincing phishing emails and text messages because genuine personal details can make fraudulent approaches appear more credible.
Sikkerdigital advises people never to disclose MitID information, one-time codes, passwords or payment-card details following unexpected contact, even when the person contacting them already knows personal information about them.
People concerned about misuse of their CPR number can also add a credit warning to their CPR record through Borger.dk. The warning signals that banks and other companies should take extra care when checking someone's identity before issuing loans or credit.
A credit warning can make it harder for someone to obtain loans or credit fraudulently, but it is not an absolute credit freeze. Companies are not required to check the CPR register for credit warnings, although many do so before granting credit.
Denmark Orders Wider CPR Security Review
Egelund has ordered a comprehensive security review of the entire CPR system following the incident.
The government says measures have already been introduced to reduce the risk of a similar event, while the CPR administration, police and other relevant authorities continue reconstructing what happened.
The ministry has cautioned that some details could be refined as investigators establish the full sequence of events. The investigation remains at an early stage.
For now, the confirmed findings point to misuse of an authorised corporate route into the CPR system rather than a publicly established direct intrusion into the central database itself.




