CPR leak: 8.8 million records stolen via 123456 password

Picture of Gitonga Riungu

Gitonga Riungu

CPR leak: 8.8 million records stolen via 123456 password

DR Nyheder reports that a small software company on Funen is at the center of the largest leak of Danish CPR numbers and addresses in the country’s history.

The company, which marketed itself on “top-secured data protection”, held a legal access to the CPR register, and that access was compromised. This was revealed on 9 October by DR. DR has not named the company, because it has not been able to reach it for comment since Thursday morning.

According to documents DR obtained through a freedom of information request, the CPR Office reported the incident to the Danish Data Protection Agency on 3 October. The report states that the data theft took place between 10 and 20 September. The company’s access to the register was blocked on 2 October.

An unusually high invoice triggered the alarm

Per the report, a CPR Administration employee noticed an unusually high invoice for the Funen company and raised the alarm. The report also states that CPR Administration runs a fixed invoicing check for abnormal usage patterns on CPR services. Further initiatives are being considered as a result of the incident.

DR’s research shows that one of the passwords used by the company had been hacked and was openly available in a data leak. The password was “123456”. DR could not establish whether that specific access was the one misused.

As reported by Politiken on 8 October, a person claiming responsibility showed the newspaper documentation for 8,749,975 CPR records and said the password was 123456. Politiken writes that the alleged hacker communicated with its journalists in English. DR states that it does not know the person’s identity or nationality.

Politiken first reported the breach on 5 October, writing that outsiders had gained access to names, addresses and CPR numbers belonging to around 8.8 million people. According to that reporting, the unauthorized access apparently took place during September 2026, and the company’s CPR access was stopped once the incident was detected.

The National Unit for Special Crime, known as NSK, is investigating the case. NSK had no comment on DR’s story, and there were no suspects as of 9 October. DR notes that responsibility for ensuring that companies with CPR access meet a sufficient security level ultimately rests with the authorities.

What the CPR leak means for foreign residents

The CPR register covers everyone registered as a resident in Denmark, including foreign nationals with a residence address here. The CPR number is the key identifier used for a bank account, doctor’s appointments, tax records and public services on borger.dk. Private companies can be granted paid access to the register, which is how the Funen company held a legal access in the first place.

Neither DR nor Politiken has published a breakdown of who is in the leaked material, so it is not known how many of the roughly 8.8 million records belong to internationals or to people who have since left Denmark. It is also not yet established how the stolen data has been used, whether any identity misuse has occurred, or who was behind the access. DR reports that there are no suspects and that the company has not commented, and the data breach remains under investigation by NSK.

author avatar
Gitonga Riungu Writer
Gitonga Riungu covers sustainability, business and politics in Denmark. Gitonga's articles add context and perspective so readers understand why a story matters.
Danish News in English for Internationals - The Danish Dream

Get the daily top News Stories from Denmark in your inbox