← Denmark CPR (Central Person Register)

2026 Denmark CPR — vendor search access abuse; ~8.8M names/addresses/CPR IDs

2026 8.8M records affected Share on X

Data compromised

Names, addresses, and CPR numbers for ~8.8M registered persons; register can also hold marital status, birth details, family relationships, Church affiliation, legal incapacitation (extras per-record not fully specified). Name/address-protection holders’ names and addresses not exposed per review so far

Technical writeup

Verified Oct 5, 2026 disclosures from Denmark’s Ministry of Research, Education and Digitalisation / CPR administration (CPH Post, Bloomberg). During September 2026, unauthorized parties misused a Danish company’s lawful CPR search access; the company’s access was blocked after discovery (CPR admin alerted Friday evening the prior week). About 8.8 million of ~11 million CPR records were affected (living, deceased, emigrated). Reported to Datatilsynet; police investigating; Minister Christina Egelund ordered a security review. Distinct from the concurrent DTUBasen university IAM incident (~200k). companyConfirmed true; recordsAffected 8800000.

Root cause

Unauthorized parties abused a private Danish company’s legitimate access to search the Central Person Register (CPR)

References