Motorstyrelsen left a security hole open in Motorregistret for nearly five years, exposing the names, addresses and birth dates of 71,080 protected citizens to 59 companies.
DR Nyheder reported on September 18 that the leak at the Danish Motor Vehicle Agency was broader than first described. DR writes that birth dates were also accessible, and that the remaining hole will not be closed until September 22, 2026.
Motorstyrelsen registered the security breach on July 4, 2025. Affected citizens were first informed in April 2026 that companies had been able to look up their names and addresses since 2021. At that time, around 73,000 people were notified.
The agency told DR that its own investigation concluded that 71,080 people were part of the breach. All of them had specifically asked for name and address protection in the register.
In separate reporting, DR lists the 59 companies with approved terminal access. They include 26 recycling centers, 22 parking companies, four debt collection firms, four financing companies, one rescue service, one state-owned company and one guarantee fund.
One of those affected is Anders Friis, who describes himself as shaken by the new information. He previously worked as a municipal SSP employee, cooperating with police on young people heading toward crime. He told DR he does not want his details available to such contacts.
Friis said a birth date functions as a key for people with bad intentions. As noted in DR’s reporting, birth dates are often part of the control questions used when a password is reset. He said he does not find the combination with his name and address reassuring.
Friis requested access to his own case file. According to that file, several recycling centers, multiple parking companies and a debt collection firm had looked up his information. He said he has never had a debt collection case, and DR reported that it tried without success to reach the firm.
Agency launches external review
Motorstyrelsen told DR that it takes the breach involving name- and address-protected citizens very seriously. The agency apologized to all affected citizens for the course of events.
The agency said it has started a closer investigation into how information from Motorregistret is released to companies. It has identified a number of follow-up tracks and is bringing in external assistance to prevent similar breaches. This is the kind of data breach that has drawn scrutiny of public IT systems in Denmark.
DR also explained the supply chain risk in the case. Sharing data with 59 companies creates 59 possible routes for attackers, raising cybersecurity concerns beyond the register itself.
Motorstyrelsen said it is currently preparing new notification letters for the people affected by the breach. The agency said its priority is to inform those citizens directly with the relevant information as quickly as possible.








