# Data Access Misused to Expose CPR Numbers of About 8.8 Million People in Denmark

*Tuesday, October 6, 2026 at 6:16 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-10-06T06:16:49.058Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 9/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/19789.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Danish authorities say unauthorized parties used a private company’s legitimate connection to the national register to pull names, addresses and CPR identification numbers for roughly 8.8 million people over a 10‑day period, triggering a major police investigation.

Denmark is dealing with a large‑scale breach of its central population register after unauthorized actors accessed names, addresses and CPR numbers for about 8.8 million people via a private company’s lawful connection to the system.

Officials say the attackers didn’t penetrate the government register directly. Instead, they took advantage of a company that already had approved access, running automated lookups for 10 days and extracting a vast quantity of personal data. Police are now investigating who carried out the automated queries, how that access was abused and what happened to the information.

The CPR number is Denmark’s core personal identifier, used across healthcare, tax, banking and public services. Combining names, addresses and CPR numbers gives criminals a strong starting point for identity theft, fraudulent borrowing and social‑engineering schemes.

Authorities haven’t yet reported large‑scale misuse directly tied to this incident, but the exposure of such a broad dataset puts banks, telecom providers and public agencies on alert. Many services in Denmark depend on digital systems that rely in part on CPR‑based checks, which means verification processes may have to be tightened.

The breach also highlights the strain on Denmark’s cybersecurity and data‑protection framework. Banks and companies using CPR data may need to add extra authentication layers rather than relying on basic identity attributes that could now be in circulation. Public bodies face similar pressure when granting access to sensitive online services.

At a structural level, the incident raises hard questions about how governments grant and monitor third‑party access to national registers. The use of automated lookups over a 10‑day span suggests that controls such as rate‑limiting or anomaly detection either failed or were insufficient to flag the pattern in time.

Denmark has been seen as a frontrunner in digital government, with tightly integrated systems built around common identifiers. This breach shows how the concentration of data in a single register, combined with trusted external connections, can turn one misused access point into a nationwide issue.

Outside observers will be watching to see whether stolen records appear on criminal markets, whether the government moves to change or supplement CPR‑based credentials, and what new rules emerge for private entities allowed to query the national register. Those steps will shape how Denmark rebuilds trust in a system that underpins most of its digital public life.
