BREACH WATCH BRIEF Critical 🔑 Threat intel

Denmark’s CPR Register Leaked Data of 8.8M Residents via Abused Third‑Party Access

Attackers Stole Data of Nearly 9M Danes from the Central Register of Persons Denmark’s residents have been hit by a data breach affecting the country’s Central Register of Persons, exposing names, addresses, CPR numbers and other details of 8.8 million people. The breach was traced to abuse of a small company’s legitimate access to the register.

SeverityCritical
Type🔑 Threat intel
ConfidenceHigh
ReportedOct 6, 2026
Government & Public Sector Government agencies managing national identity registers Financial services using CPR data for KYC/AML Enterprises that outsource access to citizen registries Third-Party Dependency Data Exfiltration
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

A small Danish company with legal access to the Central Register of Persons performed massive automated queries, extracting names, addresses and CPR numbers for 8.8 million individuals over a ten‑day period. The breach was detected after an unusually large invoice flagged irregular system behavior.

Why it matters for trust and compliance

  • Check whether the systems or suppliers named here appear in your own inventory.

Who is affected

Government agencies managing national identity registers Financial services using CPR data for KYC/AML Enterprises that outsource access to citizen registries

Recommended actions

  1. Audit all contracts and legal access rights to the CPR or similar registries.
  2. Implement real‑time monitoring, throttling, and alerting on high‑volume lookup activity.
  3. Obtain a detailed incident‑response report from the offending vendor and update breach‑notification processes.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.