Hackers exploit lawful access to steal 8.8m records from Denmark’s CPR

By Central

More than 8.8 million individuals registered in Denmark’s Central Person Register (CPR) are being notified that their personal data has been stolen in a breach that exploited a trusted company’s lawful access to the system. The incident, discovered late last week, represents one of the largest single breaches of a national population registry in European history, affecting both living and deceased individuals whose records date back decades.

The Scale of the Breach: 8.8 Million Records Compromised

The CPR, established in 1968, is Denmark’s national civil registration system and holds records on approximately 11 million people in total — including current residents, emigrants, and deceased individuals. The breach exposed the names, addresses, and CPR numbers (the equivalent of Social Security numbers) of roughly 8.8 million registrants. Only individuals who had opted into the system’s name and address protection feature are confirmed unaffected.

Authorities became aware of the intrusion on Friday when abnormal behavior was detected within the system during September. Over the following weekend, investigators confirmed that hackers had exfiltrated the data through a pipeline that was never intended for bulk extraction: a private company’s authorized access under Danish law.

How Hackers Used Lawful Access to Exfiltrate Data

Under Denmark’s Data Protection Regulation and Data Protection Act, private companies may request lawful access to the CPR to obtain information on specific individuals for legitimate business purposes — such as credit checks, identity verification, or statutory compliance. The system is designed to allow these queries on a per-person basis, not for mass data pulls.

In this case, the threat actors compromised a Danish company that held such lawful access, then used that company’s credentials to make repeated, automated requests for CPR records. The scale of the exfiltration — covering millions of people — indicates that the attackers operated the access over a sustained period, likely weeks, before system monitors flagged the anomaly. CPR did not name the company involved or the specific threat actor behind the breach, citing an ongoing investigation with the police and the Danish Data Protection Agency.

Why the Lawful Access Model Matters

The incident highlights a fundamental tension in identity governance: legitimate access mechanisms, once breached, become the most effective vector for mass data theft. Because the query system was trusted and whitelisted, it did not trigger the same alerts that would accompany a direct attack on the registry. The CPR’s security review, announced alongside the breach notification, will almost certainly need to address the monitoring of bulk or unusual query patterns from authorized third parties — a challenge that parallels issues seen in healthcare and financial data ecosystems worldwide.

What Was Stolen and What Was Not

The stolen records contain three core fields: full name, residential address, and CPR number. The CPR number — a 10-digit identifier assigned at birth or upon immigration — is used across all official interactions in Denmark, from healthcare to taxation to banking. Unlike Social Security numbers in some jurisdictions, CPR numbers are rarely changed, making lifetime fraud risk a serious concern for the 8.8 million affected.

However, the breach did not expose financial account details, passwords, biometric data, health records, or tax figures. The attackers appear to have accessed only the fields available through the lawful query interface. For the roughly 10% of registrants who had activated the name and address protection service — which removes their details from public-facing searches and bulk query results — the records were shielded.

Timeline: Detection, Notification, and Response

The incident timeline, based on official statements, is as follows:

  • September 2026: Abnormal query activity occurs within the CPR system, but is not immediately identified as malicious.
  • Late Friday (weekend): CPR is notified of the anomalous behaviour by internal monitoring systems.
  • Saturday–Sunday: Analysis confirms that a third party’s lawful access was compromised and used to extract data.
  • Monday: CPR announces the breach publicly, begins notifying affected individuals, terminates the company’s access, reports to the Danish Data Protection Agency, and launches a full investigation with police and other authorities.

CPR has urged the public to be vigilant against unsolicited communications that request passwords, personal information, or sensitive data — a common post-breach phishing tactic. The agency also stated that it cannot name the perpetrator at this stage, but intends to review and strengthen security policies to prevent recurrence.

Featured Snippet: How Did Hackers Exploit Lawful Access to Denmark’s CPR?

Hackers compromised a Danish company that had been granted lawful access to the Central Person Register under Denmark’s Data Protection Regulation. By using that company’s legitimate credentials, the attackers were able to query the CPR system and extract names, addresses, and CPR numbers for approximately 8.8 million registrants without triggering immediate alarms. The breach was only detected when monitoring systems flagged abnormal query volumes during September. Once discovered, CPR terminated the company’s access, notified the data protection authority, and launched a police investigation.

Broader Implications for National Identity Systems

Denmark’s CPR is one of the oldest and most comprehensive civil registries in the world. Its architecture reflects a 1960s design that prioritized utility over surveillance resilience: the system was built to make identity verification frictionless for both government and private sector use. Over time, that utility was extended to third parties under strict legal conditions, but the technical controls around query volume and pattern analysis appear to have lagged behind the threat landscape.

This breach is not an isolated anomaly. In recent years, similar incidents have affected national identity systems in other countries. The United Kingdom’s National Health Service has repeatedly seen third-party contractors lose credentials used to access summary care records. The United States has experienced breaches of state-level motor vehicle and voter registration databases through compromised authorized access. The common thread: any system that grants lawful bulk or frequent query access to external entities becomes a leveraged target.

The CPR case adds a new dimension because the scale — 8.8 million records — approaches the entire adult population of Denmark, plus a substantial share of emigrants and deceased individuals. The inclusion of deceased persons’ data, which is rarely updated or protected after death, may create unique risks for identity theft in contexts such as inheritance fraud, claiming of benefits, and historical document verification.

Security Response and Future Reform

CPR has indicated it will undertake a comprehensive security review. Likely changes include:

  • Enhanced monitoring of query patterns from all authorised third parties, with thresholds for bulk or anomalous activity.
  • Implementation of cryptographic or token-based access that limits what each company can retrieve and how often.
  • Mandatory reporting of any compromise of credentials used to access the system, paired with rapid revocation protocols.
  • Possible legislative reform to tighten the definition of “legitimate interest” for private companies seeking CPR access.

The Danish Data Protection Agency, which was notified within hours of the breach, will likely impose significant fines under the GDPR framework. While the breached company has not been named, it faces exposure to both regulatory penalties and civil liability claims from affected individuals.

Parallel Incidents: Recent Large-Scale Government Data Breaches

This event adds to a growing list of high-impact breaches involving government-held personal data. In 2024, the Pentagon Personnel Agency reported a breach affecting over 3 million individuals. A separate incident at a Texas healthcare firm impacted 250,000 patients, and a breach at a Washington, D.C. health agency exposed 400,000 beneficiary records. Earlier this year, the Gyazo screenshot service reported 23 million user records compromised. While the sectors differ, the underlying vulnerability — authorised access used for unauthorised extraction — recurs across all these cases.

The CPR breach stands out for its systemic targeting of a nation’s foundational identity register. Unlike breaches of commercial databases, where affected individuals can often change passwords or freeze credit, the theft of a CPR number is far more difficult to remediate because the number is tied to lifetime identity and cannot easily be reissued.

What Affected Individuals Should Do Now

CPR’s official guidance urges caution regarding unsolicited calls, emails, or text messages that request any further personal information or ask the recipient to click on links. Because the stolen data already contains names and addresses, phishing attempts may appear highly convincing — referencing the victim’s correct CPR number to establish trust.

Danish residents are advised to:

  • Monitor official communications from CPR and the Danish Data Protection Agency.
  • Report suspicious activity to the police via the country’s digital crime reporting channels.
  • Consider activating the name and address protection service if not already in use.
  • Review their credit reports with the national credit bureaus for signs of identity fraud.

For deceased persons whose records were included, family members should also be alert to attempts to use the deceased’s identity to open accounts or file fraudulent tax returns.

The Long-Term Cost of Trusted Access

Denmark’s CPR breach is a stark reminder that convenience in identity verification carries a security price. The very feature that makes the system efficient — allowing companies to query identity data with minimal friction — is the same feature that made this mass theft possible. The coming reform process will almost certainly involve trade-offs between speed of legitimate access and robustness of controls. How Denmark balances those trade-offs will be watched closely by other nations with similar civil registration systems, including Sweden, Norway, Finland, Iceland, and several countries in continental Europe that use population registers for public administration.

For the 8.8 million people receiving notification letters, the immediate concern is practical: shielding themselves from the wave of targeted phishing that historically follows such breaches. For the security community, the deeper question is whether the model of “lawful access” for private companies can ever be made safe at scale — or whether the concept itself must be fundamentally rethought in an era where nation-state and criminal groups routinely target identity infrastructure.

The CPR incident may well accelerate a shift toward self-sovereign identity models, where individuals hold their own credentials and grant permission for each query rather than relying on a central registry that third parties can access. Until such models mature, however, the tension between utility and security will remain the defining vulnerability of national population databases.

Share This Article