Denmark: CPR population registry breach affects 8.8 million people
Denmark's central population registry (CPR) has reported a breach affecting around 8.8 million registered people. The exposed names, addresses and identification numbers could be used for targeted, convincing scams.

Denmark’s central population registry, the CPR, announced on 5 October 2026 a data breach affecting around 8.8 million registered people. The news comes from Bleeping Computer, which draws on statements from the CPR and the Danish data protection authority. At this stage it is our only source, and the figures may still change: the authorities themselves say they are still working to establish the full scale of the incident.
A legitimate access turned against the registry
The CPR is Denmark’s national civil registry. It holds personal information on everyone registered in it: name, address, date of birth, marital status and CPR number, an identifier unique to each person.
The intrusion took place in September 2026. The registry’s administration discovered it on 2 October, then spent the following weekend assessing its scale. According to the CPR, the attackers did not break into the system directly. Instead, they misused the legitimate access of a private Danish company. The data protection authority says they used a brute-force approach. They tried CPR numbers in bulk to find out which ones existed, then extracted the data linked to each record they found.
It is not yet known how the company was compromised. Bleeping Computer says it asked the authority about this, but had received no answer by the time it published. The company’s access has been cut off and the police have opened an investigation. The minister responsible for digital affairs has briefed the relevant parliamentary committee and announced new security measures to prevent a similar incident from happening again.
Who is affected
The 8.8 million figure needs some context. The registry currently holds data on 11 million people, so the breach affects around 80% of them: a large majority, but not everyone. It is not limited to current residents either. It also includes people who have moved abroad and people who have died. It would therefore be wrong to say that every person living in Denmark is affected, but anyone listed in the registry has a high chance of being so, even if they no longer live in the country.
The exposed data
According to the CPR, the attackers obtained names, addresses, CPR numbers and other information about registered people. The source does not specify what that other information is. The registry also holds dates of birth and marital status, but nothing indicates at this stage whether those fields were among the extracted data.
What has been confirmed is enough to create a real risk. Taken together, a person’s name, address and national identification number allow a fraudster to pose as a government agency, a bank or a public service, with details that inspire trust.
The risks and the precautions
The authorities are urging those affected to be extremely cautious about unsolicited contact: phone calls, emails or similar messages. Their advice is simple. Never share a password or any confidential information in response to such contact, even if the person you are dealing with knows your name, your address and your CPR number.
A dedicated helpline has been set up for people who may be affected. Help and advice are also available at sikkerdigital.dk. If you have ever been registered in Denmark, including if you have since left the country, this advice applies to you.
From now on, the fact that a caller knows your identification number no longer proves who they are. That is the rule to keep in mind every time your phone rings.
Sources (1)
- Denmark population registry data breach affects 8.8 million peoplebleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


