# Denmark Data Breach Exposes CPR Details for 8.8 Million People via Third‑Party Access

*Tuesday, October 6, 2026 at 6:21 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-10-06T06:21:03.865Z (2h ago)
**Category**: cyber | **Region**: Europe
**Importance**: 9/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/19804.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Denmark says unauthorized parties accessed names, addresses and CPR national ID numbers for about 8.8 million people through automated lookups over 10 days, using a private company’s lawful connection to the national register.

Denmark has disclosed that a major slice of its national population data was exposed when unknown actors misused a private company’s legitimate link to the central register.

Authorities say the compromised data covers around 8.8 million people, roughly four out of five records in the system. The information accessed includes names, addresses and CPR numbers, the personal identifiers used throughout Danish life for tax, health services, and banking.

According to the initial account, the data was pulled through automated lookups that ran for 10 days before being detected and stopped. Police have opened an investigation. Officials have not yet said who they believe was behind the activity or what the motive was.

This wasn’t described as a direct hack of government servers. Instead, the attackers appear to have exploited the lawful access granted to a private company, using that channel to query far more records than normal business would require. The incident highlights how third‑party connections to core public databases can become the weak point in an otherwise hardened system.

For Danish residents, the exposure is serious because CPR numbers function as a central key to their interactions with both public services and private companies. With names, addresses and CPR numbers, criminals can attempt identity theft, fraudulent account openings, or highly tailored phishing and social‑engineering attacks. The data can also circulate in criminal markets for years.

Banks, telecom firms and public agencies now have to treat CPR‑based checks as potentially compromised. Many of their existing processes assume these identifiers remain confidential, so they may need to add extra verification layers and monitoring to spot misuse.

At a European level, the breach tests whether strict data‑protection laws are being matched by equally robust control over every connection into sensitive systems. Many countries in the region operate central population registers and grant access to a range of vendors for payroll, digital services and other functions. Each connection is another route for misuse if not tightly governed.

Key steps to watch next include whether Danish authorities decide to reissue CPR numbers for affected residents, how regulators advise financial and telecom sectors to adjust their identity‑verification rules, and whether reviews in other EU states uncover similar risks around third‑party access to core population data.
