Unauthorized parties used a small Danish company’s legitimate access to the CPR register to pull personal data on about 8.8 million people, and the breach was only discovered because the company received an unusually large invoice for its searches.
At a press conference in Copenhagen on Tuesday, Danish authorities said the unauthorized access ran for roughly ten days in September 2026. According to DR, the discovery came down to money. Mikkel Leihardt, a department head at the Ministry of Research, Education and Digitalisation, confirmed that a very large amount being invoiced drew attention to the unusually high level of activity.
Each search a company makes in the CPR register costs money. The large bill sent to the company, whose name authorities have not released, is what revealed that misuse had taken place. Per DR, the company itself had legal access to the register, and news of the misuse first became public on Monday.
Authorities still do not know who was behind it
Henriette Erbs, a unit head at the National Unit for Special Crime, known as NSK, said it is too early to say who is responsible or which method was used. She added that cases of this type often involve cross-border crime. The police investigation is ongoing.
Laila Reenberg, director of the Danish Agency for Societal Security, said authorities are taking the case very seriously. As she put it at the press conference, it is not known what the data harvest will be used for or who is behind it, but digital fraud is an obvious line of thinking. Leihardt said the information obtained primarily concerned names and addresses.
In a statement issued through Ritzau, CPR Administration said it became aware of irregular activity on the evening of October 2, 2026, and established the scale of the access over the following weekend. The company’s access has since been stopped. The incident has been reported to the Danish Data Protection Agency, Datatilsynet, and is being investigated by police and other relevant authorities.
As reported by Politiken, the breach affects close to nine million people, and protected names and addresses were not exposed. CPR Administration stated that the information accessed fell within the scope normally available to private companies with register access.
What the CPR breach means for foreign residents
The CPR register is Denmark’s central civil registration system. Everyone who registers a Danish address, including internationals on a residence or work permit, receives a CPR number and is listed in it. Because the figure of 8.8 million covers registered people rather than current residents, foreign nationals living in Denmark are included on the same terms as Danish citizens.
A point raised at the press conference is directly relevant here. As noted in DR’s live coverage from the briefing, authorities said a CPR number can no longer be used as a means of identification. For internationals, the CPR number is used constantly, at the doctor, in banks, at SKAT and on borger.dk, which is why the Agency for Societal Security pointed to digital fraud as the obvious risk to consider. Authorities have not announced any individual notification scheme, and it is not yet known whether the data has been used for anything.
Denmark has seen earlier incidents involving CPR data, including the case of a former student tried for selling CPR numbers to criminals and a data breach at DTU affecting around 200,000 CPR numbers. Neither case is connected to this one by any named source. What sets the September 2026 incident apart is its scale and the fact that it ran through a company with lawful register access.





