Attackers reached Denmark’s CPR, the central population register, through the legitimate access of a private company allowed to query it. Names, addresses and personal ID numbers of 8.8 million people were taken. The breach began in September and was only spotted on 2 October.

What happened

On 5 October 2026 Denmark’s Ministry of Digital Affairs announced a breach of the CPR, the central register that gives every resident a unique personal number. The attackers obtained the names, addresses and CPR numbers of 8.8 million people — more than the country’s population, because the register also keeps people who have died or moved abroad.

They did not break into the register itself: they used the legitimate access of a private Danish company that was authorised to query it. The intrusion started in September and was only detected on the evening of Friday 2 October; the company’s access was then cut, the data protection authority notified and a police investigation opened. The minister called it “an extremely serious incident”.

Why it matters beyond Denmark

A CPR number combined with a name and an address makes fake messages from banks or public services far more convincing: expect targeted phishing, SMS and phone scams. The same pattern — a supplier with legitimate access becomes the way in — hit the Hauts-de-France region in France the same weekend, where bank details of about 700,000 people were exposed through two service providers.

What to check in your own company

  1. List every third party that can read your data — integrators, outsourcers, SaaS connectors, API keys — and what each one can actually reach.
  2. Limit each access to the data and the volume it needs, with per-account quotas and IP restrictions where possible.
  3. Require strong authentication for partner accounts and API access, and rotate their keys regularly.
  4. Watch partner activity like your own: unusual volumes, night-time queries or bulk exports should raise an alert — here, the leak ran for weeks unnoticed.
  5. Write it into contracts: incident notification deadlines, security requirements and the right to audit.

Our take

Your security is only as good as that of the least protected company holding a key to your systems. Supplier access deserves the same monitoring as an administrator account — and an alert when it suddenly reads far more than usual.

Sources

Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.

Talk to an expert