Connect with us

NEWS

Denmark’s CPR Leak Came Through a Company’s Search Account

Unknown users harvested 8.8 million Danish CPR records through a small firm’s paid lookups. The state noticed when the September invoice arrived.

Published

on

Unknown users ran well over 14 million lookups against Denmark’s Central Person Register in September and pulled records on 8.8 million people. They used a small Danish company’s lawful, paid search account, and the state noticed when the bill came due on 2 October 2026.

The ministry that oversees the register called it a deeply serious incident the next Monday. Police still have not named a suspect, a country, or a motive. The door was a login the state had already issued.

They Found It on the September Invoice

Companies with a legal right to search CPR pay for each lookup. In September the unnamed firm’s account produced a charge so large that CPR staff treated it as a warning, not as a routine fee. Mikkel Leihardt, a department head at the Ministry of Research, Education and Digitalisation, told a briefing on 6 October that the size of the invoice is what made the September activity obvious.

There is a very large amount that was invoiced, which makes you aware that there has been a lot of activity.

Mikkel Leihardt, department head, Ministry of Research, Education and Digitalisation, 6 October 2026 briefing

The path had no automated alarm for this kind of search. Leihardt said the next billing cycle is 30 days, so the same traffic could have run until the following invoice if no one had opened this one. Manual watching is now in place, and the firm’s login is dead.

HOW THE HARVEST SURFACED

  1. September 2026: About ten days of lookups run through a small Danish company’s legal CPR search account.
  2. Evening of 2 October 2026: CPR staff see irregular September activity while a very large invoice is being prepared.
  3. Weekend of 3 to 4 October 2026: The office maps the scale: names, addresses and CPR numbers on about 8.8 million people, living, dead and abroad.
  4. 5 October 2026: Minister Christina Egelund publishes the incident and tells parliament’s business and digitalisation committee.
  5. 6 October 2026: Leihardt, the National Unit for Special Crime and the Agency for Societal Security brief the press at Eigtveds Pakhus.

Jacob Herbst, chair of Denmark’s Cyber Security Council, called that detection method shocking once the invoice story landed. A fee run is a finance control. It is a poor substitute for a cap on how many citizens one small firm can query in a night.

How Private Companies Query the Register

Denmark does not keep CPR behind a government-only wall. Banks, utilities, landlords and other firms with a documented interest may search or subscribe under the CPR Act’s section 38, as long as they have already identified each person by number, by name and date of birth, or by name and address, and as long as data-protection law lets them hold the result. The unknown users stayed inside that private-company slice. They did not need a stolen admin password for the whole civil file.

Two products sit on that legal base, and they are easy to confuse. A personabonnement lets a firm subscribe to a customer’s name and address and get a nightly ping when someone moves, marries, emigrates or dies. CPR’s own guidance says that product never sends the person number to a private firm, because the firm is supposed to have identified the customer already. The September incident was not that feed. It was paid search: each query billed, volume limited by the size of the invoice someone happened to read.

The state also offers a private-sector GraphQL lookup on Datafordeler, with the same legal haircut: current data only, no records marked as closed, and names and addresses stripped when a person has protection. Ministry officials have not said which pipe the small company used. They have said the queries stayed inside what private firms are allowed to receive, and that similar access at other firms has now been shut.

WHAT A PRIVATE FIRM MAY RECEIVE

  • Current name: Delivered unless the person has name protection on the file.
  • Current address: Delivered with the move date, unless address protection is on.
  • Status flags: Death, disappearance, emigration, guardianship and a contact address, each with a date.
  • Job title: Included when it is on the record.
  • The number itself: Not pushed out on a subscription; it can be typed into a search, which is how empty numbers help explain the extra lookup attempts.

Danes can log into borger.dk with MitID and see which firms hold a subscription on them. They cannot see a search log. The public transparency tool points at the quieter product. The harvest used the louder one.

The Harvest Stopped at Name, Address and Number

Leihardt said the small company’s account tried well over 14 million concrete CPR lookups and got 8.8 million hits back. Empty numbers explain the gap: the search accepts a query that matches no one. A file of hits is still a national identity list, because a Danish person number opens with the date of birth. Confirming which strings are live, then pairing each with a name and a street address, is the whole kit.

THE FILE AGAINST THE REGISTER

Slice Count
Records in CPR About 11 million
Records reached About 8.8 million
Share of the file 80 percent
Lookup attempts Well over 14 million
People living in Denmark About 6 million
Search window About ten days in September 2026

The extra records beyond the living population are people who have died or moved abroad. The about 8.8 million registered people in the ministry notice include all three groups. People who had turned on name and address protection were left out of the name and address fields, the review found. The rest of the civil file, church membership, kinship, citizenship, was not in the private-company window, which is why a full-register dump is the wrong picture of this incident and a phishing file is the right one.

Why Denmark Cannot Just Reissue Every Number

A CPR number is issued once and follows the person through tax, health, banks and benefits. Emigration does not cancel it. Death does not wipe it from the historical file. Egelund, asked whether the country would now hand everyone a new number, would not say yes or no. She has ordered a full security review of CPR with no date attached, and she said any rebuild of the system waits on that work.

This is a deeply serious incident, which is why I have also briefed the Folketing’s Business and Digitalisation Committee. Together with all relevant authorities we are mapping the full extent of the incident. We have already launched steps on CPR to prevent similar incidents. I have also asked for a thorough security review of the CPR system.

Christina Egelund, Minister for Research, Education and Digitalisation, ministry statement, 5 October 2026

She told interviewers the hole is closed and that similar access through other companies is closed too. She also said, in plain terms, that the safeguards around this firm’s access were not good enough, and that the episode should not have been possible. MitID, the national login for banks and public services, was not in the harvest, she said. The number on the yellow health card still sits underneath that login in daily life, which is why a review that only patches the search account will not be the end of the argument.

Cybersecurity specialist Jan Kaastrup has been saying the quiet part: treating the number as a secret is a broken idea, because too many offices already ask for it as if it were a password. Once 80 percent of the file is in unknown hands, that argument is no longer theoretical. Reissuing 8.8 million numbers would mean touching health cards, tax, banks, pensions and every firm that stores the old string. That is why the minister will not promise it on the steps of a briefing.

Pharmacies, Lenders and Records of the Dead

Laila Reenberg, director of the Agency for Societal Security, told the 6 October briefing that the harvesters’ aim is still unknown, and that digital fraud is the obvious working theory. She also said a CPR number should no longer stand alone when someone is asked to prove who they are. Pharmacies have already tightened checks on medicine and health information, so a number recited at the counter is not enough on its own.

The useful crime is not a film-plot takeover of a bank app. It is a phone call or a text that already knows your name, your street and your number, then asks for a MitID code, a card PIN, or a one-time password. The ministry’s own notice tells people never to hand over codes even when the caller recites those three fields. Sikkerdigital.dk is the government’s advice page. The digital-security hotline on +45 33 37 00 37 extended its hours to 08:00 to 24:00 in the days after the notice.

Webshops that still open store credit on a CPR number were already a weak point before September. That older fraud does not prove this file is in use. It shows why a national dump of numbers, names and addresses is valuable to anyone who sells confidence tricks. Records of the dead are useful in the same trade: a deceased person’s number, paired with a live address history, is a way to open accounts that no one is watching. People living abroad stay in the register, so the file travels with them.

The firms that legally query CPR are now in a worse place too. A match on name, address and number no longer shows that the applicant is the person on the file. It shows that the applicant has data that unknown users also have. Lenders and others that leaned on a register match as a check have to put MitID or a chip-read identity document in front of that match, or they are confirming a leak, not a person.

Police Have Named No Suspect

The CPR administration stopped the company’s access, notified Datatilsynet, and handed the case to police. Henriette Erbs, a unit head at the National Unit for Special Crime, said on 6 October that it is too early to name who did it or how, and that this type of case is often cross-border. NSK has been at the company, has spoken with foreign police, and has charged no one. Egelund has not ruled out an international track.

WHAT WE KNOW

  • The channel: A small unnamed Danish company’s legal, billed CPR search account, used for about ten days in September 2026.
  • The take: Names, addresses and CPR numbers on about 8.8 million people; protected names and addresses excluded.
  • The detector: A very large September invoice, noticed on the evening of 2 October 2026, with no automated alarm on that path.

WHAT IS UNCONFIRMED

  • The actor: No suspect, no country, no claim of responsibility.
  • The motive: Fraud is the working theory, not a finding.
  • The fix: No decision on new numbers, and no date on the security review of CPR.

The unnamed company is still the hole in the public account. Until that firm is identified, Danes cannot tell whether their own bank, insurer or landlord sat one office away from the login that emptied most of the register. The review Egelund ordered will have to treat every other billed search account as the same kind of door, because the last alarm was a line on an invoice.

Harry is the editor of BLUE HOLE MEN, his own independent publication and the product of ten years in journalism that moved him from reporting to editing. Attribution is where he is most exacting. A quotation is reproduced from the transcript or recording, a paraphrase is labelled as one, and a claim from a press release is described as a company's claim rather than as fact. Unnamed sources are used rarely, and when they are, the article explains why the name is withheld and what the person is in a position to know. Statistics are attributed to the dataset or filing they came from, and every one is checked before publication. That standard governs the whole site, which covers news, business, technology and science together with sports, entertainment, lifestyle, travel, auto and gaming, for readers across many countries. Reviews in the technology, auto and gaming pages rest on products Harry has used himself. Errors are corrected under a public corrections policy, with the correction visible on the article. Reader mail reaches him at support@blueholemen.com.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending