Denmark's National ID System Was Breached. 8.8M Records Exposed
Key Takeaways
- Unauthorized parties gained access to personal data linked to approximately 8.8 million people from Denmark's Central Person Register (CPR) in September 2026, exploiting a legitimate access pathway held by a Danish company.
- The exposed data includes names, addresses, and CPR numbers — Denmark's national civil identification numbers. The register can also contain marital status, family relationships, birth registration details, church affiliation, and legal incapacitation status.
- The CPR system contains records for approximately 11 million people total, meaning the breach affected around 80% of all records in the system.
- The company whose access was abused has had that access blocked. Police are investigating, and the case has been reported to Datatilsynet, Denmark's Data Protection Agency.
- Denmark's Minister for Research, Education and Digitalization called it "a deeply serious incident" and announced a thorough security review of the CPR system.
According to Denmark's Ministry of Research, Education and Digitalization and the Copenhagen Post, unauthorized parties accessed the Central Person Register in September 2026 by exploiting a legitimate search capability held by a Danish company — meaning the attackers didn't break into the system directly, but used authorized access credentials to extract data they had no right to take. The CPR administration became aware of the breach on Friday, October 3, and has since blocked the abused company's access.
The scale is significant. The CPR system holds records for approximately 11 million people — Danish residents, people who have emigrated, and the deceased. Of those, around 8.8 million records were accessed without authorization. That's roughly four in five records in the entire system, and a figure that exceeds Denmark's current population of approximately 5.9 million living residents, because the register includes historical records.
The data exposed includes names, home addresses, and CPR numbers — Denmark's national civil identification numbers, which function similarly to Social Security numbers in the US or National Insurance numbers in the UK. Beyond those core fields, the register can also hold marital status, birth registration details, family relationships, church affiliation, and information about legal incapacitation. The ministry has not specified exactly which additional fields were accessed in each case.
One partial exception: people who had registered for name and address protection — a privacy opt-in that shields those details from general access — are reported to have had their names and addresses protected in this incident.
Why This Category of Breach Is Particularly Damaging
A CPR number isn’t a password. It can't be changed. It's tied to a person for their entire life — through their tax records, healthcare, banking, government services, and legal identity. When it ends up in the wrong hands, the exposure doesn't expire. There's no rotation, no reset, no way to issue a new one.
This is the specific problem with national civil registration breaches that makes them categorically worse than, say, a stolen email and password. A leaked password gets changed. A leaked CPR number, combined with a name and address, is a permanent piece of identity infrastructure that can be used for fraud, impersonation, and social engineering indefinitely. The people whose data was accessed in September 2026 will be managing the consequences of this breach for years, potentially decades.
We've been tracking identity verification breaches for some time — our research documented 88 such incidents since 2011, affecting at least 2.15 billion records on a confirmed basis. The Denmark CPR breach is a specific variant: not a commercial verification vendor, but a national government register accessed through an abused legitimate pathway. The mechanism is different; the outcome for the people affected is similar.
What the "Legitimate Access" Vector Means
National government registers are generally well-defended at the perimeter. The attack surface isn't the system itself; it's the network of authorized parties who can query it for legitimate purposes. That network is necessarily large: businesses, healthcare providers, government agencies, and financial institutions all have reasons to verify identity against a national register.
Every one of those authorized access points is a potential vector for abuse, either through compromise of the authorized party's credentials or, as appears to be the case here, through the authorized party itself or someone with access to its systems.
Blocking the abused company's access is the immediate fix. The systemic question is how an authorized query of 8.8 million records — roughly 80% of everything in the system — didn't trigger an alert before October 3. Legitimate business uses of a national register rarely require bulk access at that scale. That's the gap a security review will need to address.
What Comes Next
The CPR administration is working with specialists and other authorities to establish the full extent of the breach. Datatilsynet received notification on Sunday and is processing the case; the agency said it can't yet assess the specific circumstances or comment further. Police are investigating.
Denmark's minister has called for a thorough security review of the CPR system and said measures to reduce the risk of similar incidents have already been introduced. People in Denmark have been advised to remain vigilant and follow official digital security guidance — which, given that the primary data exposed is the kind that can't be changed, is advice with limited practical content. Vigilance against phishing and identity fraud is always sensible. It doesn't undo the fact that a permanent civil identification number is now in the hands of parties who have no right to it.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
