Unauthorised parties gained access to names, addresses and CPR numbers belonging to around 8.8 million people in Denmark by misusing a small Danish company’s lawful access to the CPR register.
The access took place over roughly ten days in September 2026, DR reports. The exposed information covered names, addresses and CPR numbers. On Tuesday morning, DR opened a live session for readers to send in questions about the case.
Answering those questions were DR’s legal correspondent, Louise Dalsgaard, and Sofie Freja Christensen, head of cyber risk and offensive security at the firm Consica. The session was set to begin at 9 a.m. DR framed it around three points: how much is known, why the theft is a problem, and what people can do themselves.
How the register was reached and who is investigating
According to The Copenhagen Post, the unauthorised parties did not break into the register directly. They instead used a private Danish company’s legitimate right to search the CPR system. The outlet reports that the figure of about 8.8 million people covers individuals registered in Denmark’s CPR system.
The CPR administration blocked the company’s access after the incident was discovered, per the same report. The case has been reported to Denmark’s Data Protection Agency, Datatilsynet, and police are investigating. People who have name and address protection registered were not included in the unauthorised access.
The Copenhagen Post also reports that authorities say it is too early to decide whether affected people need new CPR numbers. The same report states that the access has been closed. No decision on replacement numbers had been announced as of October 6, 2026.
What the CPR breach means for internationals living in Denmark
The CPR number is the personal identification number issued when a person is registered as a resident in Denmark. It is used for tax, healthcare, schooling, public services on borger.dk and for opening a bank account. Everyone registered in the CPR system holds one, regardless of nationality or residence permit type.
Because the access covered the register itself rather than one company’s customer list, foreign residents registered in CPR fall inside the group described by DR and The Copenhagen Post. The combination exposed, name, address and CPR number, is the same set of details used in everyday identification in Denmark. Authorities have reported the case to Datatilsynet and have not yet said whether new CPR numbers will be issued.
Earlier CPR cases in Denmark
Danish CPR data has been the subject of other recent cases. In 2025, the Technical University of Denmark disclosed a data breach in which up to 200,000 CPR numbers may have been stolen. A separate case saw a former student go on trial for selling CPR numbers to criminals.
Those cases involved far smaller numbers of people than the September 2026 incident. DR has not linked them to the current case. The live question session was the outlet’s response to reader uncertainty about what the access means in practice.





