Security
Denmark Has Lost the Name, Address and CPR Number of 8.8 Million People. Nothing Was Broken Into — a Licensed Company's Access Was Used as Designed
Unauthorised parties pulled the name, address and CPR number of 8.8 million people out of Denmark's Central Person Register through a private company's legitimate access, running unnoticed for a month. The register's defences were never touched.
MAI
Denmark's Ministry of Research, Education and Digitalisation said on Monday that unauthorised parties obtained the name, address and CPR number of roughly 8.8 million people registered in the Central Person Register. The register holds about 11 million records covering the living, the dead and those who have emigrated since the system began in 1968. Four out of five of those records are now in someone else's hands.
Nothing was broken into. According to the ministry, the data was pulled out through a private Danish company that holds authorised access to the register, using that company's legitimate permissions to run lookups at a scale no legitimate business process would need. The access ran through September and was only spotted on 2 October, when irregular activity surfaced. The company's access has been cut off, the police have opened an investigation, the Data Protection Authority has been notified, and the minister briefed the Folketing's business and digitalisation committee before going public on 5 October.
"Det er en dybt alvorlig hændelse." — Christina Egelund, Minister for Research, Education and Digitalisation
What was taken, and what was not
| Exposed | Not exposed |
|---|---|
| Full name | Financial or tax records |
| Address | Health records |
| CPR number (the 10-digit national identifier) | Login credentials or MitID material |
| Records of deceased and emigrated persons | Anyone registered for name and address protection |
The exclusion at the bottom right matters more than it looks. Danes who have applied for navne- og adressebeskyttelse — typically people with reason to fear being found — were not in the extracted set. For everyone else, the register's core identity triple is gone.
What stops this from being an identity-theft catastrophe is MitID. Denmark moved sensitive digital action — banking, government services, signing — behind a hardware- and app-backed second factor years ago. A CPR number is not a credential there, and knowing one does not let anyone act as you. The realistic harm is narrower and uglier: a caller who already knows your name, your address and your CPR number is extremely convincing, and convincing callers are how MitID approvals get socially engineered out of people. The ministry's own advice reflects exactly that threat model — never hand over passwords or codes over the phone or by email, even when the caller knows your personal details. Citizens were pointed at sikkerdigital.dk and the national cyber hotline, whose hours were extended to 8am–midnight.
The failure is in the model, not the perimeter
Denmark's CPR is one of the most useful pieces of public infrastructure in Europe. Banks, insurers, landlords, employers, healthcare and hundreds of private firms query it because a single authoritative identity register removes an enormous amount of friction from an economy. That usefulness is bought by granting access widely. Every grant is a copy of the register's risk, handed to an organisation whose security the register does not control.
So the attack surface of a national population register is not the register. It is the weakest of its licensees. Danish public broadcaster DR's reporting carried an academic assessment calling this the largest breach of the CPR register on record, and it was achieved without touching the register's defences at all — by standing inside a door someone else was holding open.
That reframes the remediation. A comprehensive security review of the CPR system, which the minister has ordered, will not find much wrong with the CPR system. The control that was missing sits one layer up: volume and behaviour monitoring on authorised access, so that a licensee suddenly performing bulk automated lookups for weeks trips an alarm in days rather than a month. Authorised access is still access, and treating a valid credential as an answer rather than a question is how a month of mass extraction looks like normal traffic.
The number was never a secret
The deeper problem is older than this incident. The CPR number does two incompatible jobs: it identifies you everywhere, and it has been treated, informally, as semi-confidential — something a legitimate party would plausibly know and a stranger would not. That premise has been eroding for years through every leak, every form, every supplier. As of Monday it is finished for 8.8 million people.
The constructive reading is that Denmark should stop defending the number and finish the architecture it already started with MitID: treat the CPR number as a public identifier, assume adversaries have it, and ensure nothing anywhere grants trust on the strength of knowing it. Any Danish organisation still using a CPR number as a verification question needs to stop this week. That is a change in how identity is proved, not in how a database is guarded — and it is the only version of this fix that survives the next licensee being compromised.
Sources: Forsknings-, Uddannelses- og Digitaliseringsministeriet press release · CPR-kontoret notice · BleepingComputer · Cybernews · The Irish Times · DR live coverage · DR expert assessment
Cover image: Foto: Uddannelses- og Forskningsministeriet.