[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHpo8AVclo0X3mcOCuNbtEGdeT9xZoS6l60-56pBkaLM":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"4c59e336-3dd8-40b4-9b02-085d79a42fe6","Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access","denmark-s-cpr-breach-exposes-8-8-million-people-as-experts-warn-over-trusted-thi-21d02e","Personal details belonging to around 8.8 million people have been exposed in a breach of Denmark’s Central Person Register (CPR), after unauthorised parties abused a Danish company’s legitimate access to the national civil registration system, authorities confirmed on Monday. According to the Ministry of Research, Education and Digitalisation, the compromised information includes names, addresses and […] The post Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access appeared first on IT Security Guru.","Unauthorised parties exploited a Danish company's legitimate access to Denmark's Central Person Register (CPR), exposing personal details of approximately 8.8 million people (roughly 80% of Denmark's registered population). The breach included names, addresses, CPR numbers, and status information; individuals with name\u002Faddress protection were not affected. Security experts warn the incident highlights risks of centralised national databases with third-party access and the structural value of the dataset for state-level intelligence operations and long-term targeting.","Denmark's Central Person Register breached exposing 8.8M citizens' names, addresses, and CPR numbers via compromised","Personal details belonging to around 8.8 million people have been exposed in a breach of Denmark’s Central Person Register (CPR), after unauthorised parties abused a Danish company’s legitimate access to the national civil registration system, authorities confirmed on Monday. According to the Ministry of Research, Education and Digitalisation, the compromised information includes names, addresses and CPR numbers, along with other data held in the register. Minister Christina Egelund called it “a deeply serious incident” and said she had briefed the Folketing’s Business and Digitalisation Committee. The company’s access to the system has since been blocked. “The Danish Ministry of Research, Education and Digitalisation has released a statement regarding a cybersecurity incident affecting a large volume of data subjects,” said Nathan Davies-Webb, Principal Consultant at Acumen Cyber. “Approximately 8.8 million people are impacted, which represents roughly 80% of the ~11 million individuals registered in the system.” The register covers people currently living in Denmark as well as those who have died or moved abroad. Beyond core identity details, it can hold information on marital status, birth registration, family relationships, membership of the Church of Denmark and legal incapacity, although the ministry has not said exactly which fields were accessed in each case. The initial review indicates that people registered for name and address protection were not affected. “The exposed data includes names, addresses and CPR numbers, along with a person’s status (living, emigrated, deceased), which provides a helpful basis for social engineering and ID fraud,” Davies-Webb said. “There is limited information on how the data was accessed, although the statement confirms the access came from abuse of a private Danish company’s legitimate access to the system. No attribution has been made public at this stage, so further detail is speculative.” A universal identifier, exposed For Simon Pamplin, CTO at Certes, the significance lies in what the CPR number unlocks. “The Danish CPR breach represents something more fundamental than a large-scale data incident,” he said. “The CPR number functions as a universal identifier across Danish society, underpinning access to healthcare, banking, public services, tax administration and legal status. Exposing it for 8.8 million people, encompassing the vast majority of everyone who has ever been registered in Denmark, creates a liability that extends across virtually every system those individuals interact with.” He added: “CPR numbers combined with names, addresses, marital status and family relationships create a dataset of exceptional depth and permanence. These are not credentials that can be rotated or reset. For the individuals affected, the exposure is indefinite.” Pamplin also warned that the value of the data goes well beyond everyday fraud. “The scale also means the data carries structural value beyond individual fraud. A dataset covering the near-entirety of Denmark’s registered population is precisely the kind of material that attracts state-level interest, enabling intelligence operations, social mapping and long-term targeting well beyond opportunistic criminal exploitation. Harvest now, decrypt later tactics were built for datasets of exactly this nature and permanence.” Trusted access as the weak point The route in has drawn particular attention. “This incident demonstrates the inherent risk of highly centralised national databases when private companies are granted direct access to sensitive records,” said Dray Agha, senior manager, tactical response at Huntress. “A compromised account at a single supplier can bypass an organisation’s core security controls and turn a legitimate connection into a massive data exposure.” Pamplin agreed that the method was revealing. “The attack vector here is particularly instructive. Unauthorised access was achieved by exploiting a legitimate company’s authorised access to the system. Perimeter controls, authentication layers and access governance were present and functioning. The data was readable to anyone operating within the bounds of that legitimate access, and that readability was the vulnerability.” Jamie Akhtar, CEO and Co-founder of CyberSmart, said: “The breach of Denmark’s Central Person Register has exposed names, addresses and personal identification numbers belonging to around 8.8 million people, including those who have died or emigrated. According to reports, attackers exploited a private company’s legitimate access to the register.” “This highlights how access granted to third parties can become a route to sensitive information, with exposed personal details potentially helping criminals impersonate individuals or make scams more convincing,” Akhtar continued. Questions over detection The ministry says the activity took place during September, and that the CPR administration only became aware of it on Friday evening last week. Davies-Webb pointed to this gap. “There is an interesting section in the statement in the most recent statement which suggests there may have been a delay in detection: ‘On the evening of Friday 2 October 2026, the CPR administration became aware that there had been irregular behaviour in the CPR system during September’ (translated),” he said. “While this may not be a direct factor in this case, delays are common when a breach originates from a third-party. It highlights why organisation must perform substantial due diligence to ensure breach notifications from external parties match the internal standard.” The case has been reported to Datatilsynet, the Danish Data Protection Agency, which received notification on Sunday and said it could not yet comment on the specifics. Police are also investigating, and Egelund has ordered a thorough security review of the CPR system. What those affected should do Egelund has urged people in Denmark to stay vigilant and follow official digital security guidance in the coming weeks. “Anyone affected should remain alert to phishing emails, text messages and calls, particularly those claiming to come from banks or public authorities,” said Akhtar. “Knowing your name, address or identification number does not make a caller trustworthy.” He went on: “Customers must verify requests through an official website or a known telephone number, check accounts for unusual activity and report suspected fraud promptly. Change any passwords known or suspected to be compromised, including wherever they have been reused, and enable multi-factor authentication (MFA), or passkeys where available. Changing a password cannot undo the exposure of personal information, but it can help protect an affected account.” “For the future, individuals should use unique passwords stored in a password manager, keep devices updated and make secure authentication a habit.” Lessons for organisations For organisations holding sensitive data, the experts’ message centred on supplier access and monitoring. “To defend against this threat, governments and businesses must also strictly limit what external partners are allowed to view,” said Agha. “They must also monitor these systems continuously to detect unusual search patterns before millions of records are extracted.” Akhtar said: “Organisations must take responsibility for protecting the information entrusted to them. Collect and retain only what they need, restrict access to what each user or supplier requires, and monitor for unusual activity. Regular supplier security reviews, staff training and rehearsed incident response plans should support these controls. This incident is a reminder that a trusted supplier’s access needs the same scrutiny as an organisation’s own systems.” Davies-Webb added: “This breach also highlights the importance of assessing risk correctly and going beyond identifying systems that serve a critical function. Many cyber security frameworks recommend quantify","https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F10\u002F05\u002Fdenmarks-cpr-breach-exposes-8-8-million-people-as-experts-warn-over-trusted-third-party-access\u002F?utm_source=rss&utm_medium=rss&utm_campaign=denmarks-cpr-breach-exposes-8-8-million-people-as-experts-warn-over-trusted-third-party-access","https:\u002F\u002Fwww.itsecurityguru.org\u002Fwp-content\u002Fuploads\u002F2026\u002F10\u002FDenmark-Data-Breach_-Stolen-Identities.png","2026-10-05T13:32:46+00:00","2026-10-05T14:00:24.747818+00:00",9,[18,21],{"name":19,"type":20},"Central Person Register (CPR)","technology",{"name":22,"type":23},"Danish Ministry of Research, Education and Digitalisation","vendor","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":24,"icon":26,"name":27,"slug":28},null,"Breaches","breaches",[30,35,40,45],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":46},{"id":47,"icon":26,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]