Attackers reached Denmark’s CPR, the central population register, through the legitimate access of a private company allowed to query it. Names, addresses and personal ID numbers of 8.8 million people were taken. The breach began in September and was only spotted on 2 October.
What happened
On 5 October 2026 Denmark’s Ministry of Digital Affairs announced a breach of the CPR, the central register that gives every resident a unique personal number. The attackers obtained the names, addresses and CPR numbers of 8.8 million people — more than the country’s population, because the register also keeps people who have died or moved abroad.
They did not break into the register itself: they used the legitimate access of a private Danish company that was authorised to query it. The intrusion started in September and was only detected on the evening of Friday 2 October; the company’s access was then cut, the data protection authority notified and a police investigation opened. The minister called it “an extremely serious incident”.
Why it matters beyond Denmark
A CPR number combined with a name and an address makes fake messages from banks or public services far more convincing: expect targeted phishing, SMS and phone scams. The same pattern — a supplier with legitimate access becomes the way in — hit the Hauts-de-France region in France the same weekend, where bank details of about 700,000 people were exposed through two service providers.
What to check in your own company
- List every third party that can read your data — integrators, outsourcers, SaaS connectors, API keys — and what each one can actually reach.
- Limit each access to the data and the volume it needs, with per-account quotas and IP restrictions where possible.
- Require strong authentication for partner accounts and API access, and rotate their keys regularly.
- Watch partner activity like your own: unusual volumes, night-time queries or bulk exports should raise an alert — here, the leak ran for weeks unnoticed.
- Write it into contracts: incident notification deadlines, security requirements and the right to audit.
Our take
Your security is only as good as that of the least protected company holding a key to your systems. Supplier access deserves the same monitoring as an administrator account — and an alert when it suddenly reads far more than usual.
Sources
- 01net — Fuite « extrêmement grave » en Europe : les données de 8 millions de personnes compromises au Danemark
- BleepingComputer — Denmark population registry data breach affects 8.8 million people
- 01net — Cyberattaque contre la Région Hauts-de-France, les RIB de 700 000 Français compromis
Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.
Talk to an expert