NEWS
Denmark’s CPR Leak Came Through a Company’s Search Account
Unknown users harvested 8.8 million Danish CPR records through a small firm’s paid lookups. The state noticed when the September invoice arrived.
Unknown users ran well over 14 million lookups against Denmark’s Central Person Register in September and pulled records on 8.8 million people. They used a small Danish company’s lawful, paid search account, and the state noticed when the bill came due on 2 October 2026.
The ministry that oversees the register called it a deeply serious incident the next Monday. Police still have not named a suspect, a country, or a motive. The door was a login the state had already issued.
They Found It on the September Invoice
Companies with a legal right to search CPR pay for each lookup. In September the unnamed firm’s account produced a charge so large that CPR staff treated it as a warning, not as a routine fee. Mikkel Leihardt, a department head at the Ministry of Research, Education and Digitalisation, told a briefing on 6 October that the size of the invoice is what made the September activity obvious.
There is a very large amount that was invoiced, which makes you aware that there has been a lot of activity.
Mikkel Leihardt, department head, Ministry of Research, Education and Digitalisation, 6 October 2026 briefing
The path had no automated alarm for this kind of search. Leihardt said the next billing cycle is 30 days, so the same traffic could have run until the following invoice if no one had opened this one. Manual watching is now in place, and the firm’s login is dead.
HOW THE HARVEST SURFACED
- September 2026: About ten days of lookups run through a small Danish company’s legal CPR search account.
- Evening of 2 October 2026: CPR staff see irregular September activity while a very large invoice is being prepared.
- Weekend of 3 to 4 October 2026: The office maps the scale: names, addresses and CPR numbers on about 8.8 million people, living, dead and abroad.
- 5 October 2026: Minister Christina Egelund publishes the incident and tells parliament’s business and digitalisation committee.
- 6 October 2026: Leihardt, the National Unit for Special Crime and the Agency for Societal Security brief the press at Eigtveds Pakhus.
Jacob Herbst, chair of Denmark’s Cyber Security Council, called that detection method shocking once the invoice story landed. A fee run is a finance control. It is a poor substitute for a cap on how many citizens one small firm can query in a night.
How Private Companies Query the Register
Denmark does not keep CPR behind a government-only wall. Banks, utilities, landlords and other firms with a documented interest may search or subscribe under the CPR Act’s section 38, as long as they have already identified each person by number, by name and date of birth, or by name and address, and as long as data-protection law lets them hold the result. The unknown users stayed inside that private-company slice. They did not need a stolen admin password for the whole civil file.
Two products sit on that legal base, and they are easy to confuse. A personabonnement lets a firm subscribe to a customer’s name and address and get a nightly ping when someone moves, marries, emigrates or dies. CPR’s own guidance says that product never sends the person number to a private firm, because the firm is supposed to have identified the customer already. The September incident was not that feed. It was paid search: each query billed, volume limited by the size of the invoice someone happened to read.
The state also offers a private-sector GraphQL lookup on Datafordeler, with the same legal haircut: current data only, no records marked as closed, and names and addresses stripped when a person has protection. Ministry officials have not said which pipe the small company used. They have said the queries stayed inside what private firms are allowed to receive, and that similar access at other firms has now been shut.
WHAT A PRIVATE FIRM MAY RECEIVE
- Current name: Delivered unless the person has name protection on the file.
- Current address: Delivered with the move date, unless address protection is on.
- Status flags: Death, disappearance, emigration, guardianship and a contact address, each with a date.
- Job title: Included when it is on the record.
- The number itself: Not pushed out on a subscription; it can be typed into a search, which is how empty numbers help explain the extra lookup attempts.
Danes can log into borger.dk with MitID and see which firms hold a subscription on them. They cannot see a search log. The public transparency tool points at the quieter product. The harvest used the louder one.
The Harvest Stopped at Name, Address and Number
Leihardt said the small company’s account tried well over 14 million concrete CPR lookups and got 8.8 million hits back. Empty numbers explain the gap: the search accepts a query that matches no one. A file of hits is still a national identity list, because a Danish person number opens with the date of birth. Confirming which strings are live, then pairing each with a name and a street address, is the whole kit.
THE FILE AGAINST THE REGISTER
| Slice | Count |
|---|---|
| Records in CPR | About 11 million |
| Records reached | About 8.8 million |
| Share of the file | 80 percent |
| Lookup attempts | Well over 14 million |
| People living in Denmark | About 6 million |
| Search window | About ten days in September 2026 |
The extra records beyond the living population are people who have died or moved abroad. The about 8.8 million registered people in the ministry notice include all three groups. People who had turned on name and address protection were left out of the name and address fields, the review found. The rest of the civil file, church membership, kinship, citizenship, was not in the private-company window, which is why a full-register dump is the wrong picture of this incident and a phishing file is the right one.
Why Denmark Cannot Just Reissue Every Number
A CPR number is issued once and follows the person through tax, health, banks and benefits. Emigration does not cancel it. Death does not wipe it from the historical file. Egelund, asked whether the country would now hand everyone a new number, would not say yes or no. She has ordered a full security review of CPR with no date attached, and she said any rebuild of the system waits on that work.
This is a deeply serious incident, which is why I have also briefed the Folketing’s Business and Digitalisation Committee. Together with all relevant authorities we are mapping the full extent of the incident. We have already launched steps on CPR to prevent similar incidents. I have also asked for a thorough security review of the CPR system.
Christina Egelund, Minister for Research, Education and Digitalisation, ministry statement, 5 October 2026
She told interviewers the hole is closed and that similar access through other companies is closed too. She also said, in plain terms, that the safeguards around this firm’s access were not good enough, and that the episode should not have been possible. MitID, the national login for banks and public services, was not in the harvest, she said. The number on the yellow health card still sits underneath that login in daily life, which is why a review that only patches the search account will not be the end of the argument.
Cybersecurity specialist Jan Kaastrup has been saying the quiet part: treating the number as a secret is a broken idea, because too many offices already ask for it as if it were a password. Once 80 percent of the file is in unknown hands, that argument is no longer theoretical. Reissuing 8.8 million numbers would mean touching health cards, tax, banks, pensions and every firm that stores the old string. That is why the minister will not promise it on the steps of a briefing.
Pharmacies, Lenders and Records of the Dead
Laila Reenberg, director of the Agency for Societal Security, told the 6 October briefing that the harvesters’ aim is still unknown, and that digital fraud is the obvious working theory. She also said a CPR number should no longer stand alone when someone is asked to prove who they are. Pharmacies have already tightened checks on medicine and health information, so a number recited at the counter is not enough on its own.
The useful crime is not a film-plot takeover of a bank app. It is a phone call or a text that already knows your name, your street and your number, then asks for a MitID code, a card PIN, or a one-time password. The ministry’s own notice tells people never to hand over codes even when the caller recites those three fields. Sikkerdigital.dk is the government’s advice page. The digital-security hotline on +45 33 37 00 37 extended its hours to 08:00 to 24:00 in the days after the notice.
Webshops that still open store credit on a CPR number were already a weak point before September. That older fraud does not prove this file is in use. It shows why a national dump of numbers, names and addresses is valuable to anyone who sells confidence tricks. Records of the dead are useful in the same trade: a deceased person’s number, paired with a live address history, is a way to open accounts that no one is watching. People living abroad stay in the register, so the file travels with them.
The firms that legally query CPR are now in a worse place too. A match on name, address and number no longer shows that the applicant is the person on the file. It shows that the applicant has data that unknown users also have. Lenders and others that leaned on a register match as a check have to put MitID or a chip-read identity document in front of that match, or they are confirming a leak, not a person.
Police Have Named No Suspect
The CPR administration stopped the company’s access, notified Datatilsynet, and handed the case to police. Henriette Erbs, a unit head at the National Unit for Special Crime, said on 6 October that it is too early to name who did it or how, and that this type of case is often cross-border. NSK has been at the company, has spoken with foreign police, and has charged no one. Egelund has not ruled out an international track.
WHAT WE KNOW
- The channel: A small unnamed Danish company’s legal, billed CPR search account, used for about ten days in September 2026.
- The take: Names, addresses and CPR numbers on about 8.8 million people; protected names and addresses excluded.
- The detector: A very large September invoice, noticed on the evening of 2 October 2026, with no automated alarm on that path.
WHAT IS UNCONFIRMED
- The actor: No suspect, no country, no claim of responsibility.
- The motive: Fraud is the working theory, not a finding.
- The fix: No decision on new numbers, and no date on the security review of CPR.
The unnamed company is still the hole in the public account. Until that firm is identified, Danes cannot tell whether their own bank, insurer or landlord sat one office away from the login that emptied most of the register. The review Egelund ordered will have to treat every other billed search account as the same kind of door, because the last alarm was a line on an invoice.
-
NEWS1 month agoTozorakimab Opens a COPD Lane Other Biologics Shut
-
ENTERTAINMENT1 month agoAstro City Still Pays Off a 1995 Superhero Wager
-
NEWS1 month agoAcetaminophen Liver Injuries Soared After a Narrow FDA Cap
-
BUSINESS1 month agoCalvin Klein’s Record Jung Kook Collab Could Not Lift Sales
-
GAMING1 month agoSony’s 10 Percent Disc Cut Leaves New Games Digital
-
BUSINESS1 month agoTrump’s Embargo Threat Spends the Leverage It Needs
-
ENTERTAINMENT1 month agoLionel Richie Faces Heart Tests After the Muny Show
-
NEWS1 month agoTexas Puts a Human on Every Consequential AI Decision
