Denmark’s Digitalisation Agency confirmed delays on the CPR register-insight website on October 5, 2026, after the government disclosed that unauthorized parties had accessed CPR data on 8.8 million registered people.
The website where residents can check which companies have access to their CPR information was unavailable for a short period during the morning. As DR Nyheder reports, the Digitalisation Agency confirmed delays caused by heavy traffic, but did not confirm that the site was down.
The agency also told DR that it has no overview of how many people have contacted it about the breach. The reason given was the sheer volume of inquiries. Some of those inquiries concerned setting up a credit warning in the CPR system.
What was accessed and how
According to TV 2, the compromised information includes names, addresses and CPR numbers for around 8.8 million registered people. The unauthorized access was obtained by misusing a private Danish company’s legitimate access to search the CPR register.
TV 2 adds that people with protected names and addresses were not affected, based on the review carried out so far. The affected group covers living residents, people who have moved abroad and deceased people.
Christine Engel Christensen, deputy director of the Danish Agency for Societal Security, told DR that residents should assume they are probably covered by the leak. The CPR system holds about 11 million registered people in total. She said CPR details such as name, address or CPR number can make fraud attempts look more official.
Per her comments to DR, the agency expects attempts by people posing as authorities. These may arrive by phone, email or text, asking the recipient to click a link or hand over MitID credentials or passwords. She stated that such information should never be given out.
Investigation and political briefing
The National Unit for Special Crime announced earlier on October 5 that it has opened an investigation into the CPR intrusion. DR reports that members of the Business and Digitalisation Committee and the Foreign and Defence Committee were set to be briefed at 4 p.m. the same day.
The briefing was to be given by Christina Egelund (M), minister for research, education and digitalisation. No further details about the scope of the investigation were given in the reporting.
What the CPR leak means for internationals in Denmark
The CPR number is the personal identification number issued to everyone registered in Denmark, including foreign workers, students and family members. It is used for banking, doctor appointments, tax records and signing contracts. Because the leak covers 8.8 million of the roughly 11 million people in the register, most internationals who have ever been registered here are likely included, per the Agency for Societal Security.
One of the measures the Agency for Societal Security pointed to is a credit warning, a marker in the CPR register that makes it harder to take out loans or credit in your name. DR reports that some of the inquiries received by the Digitalisation Agency on October 5 concerned exactly that. People who have moved abroad after living in Denmark are also among the registered people in the system, according to TV 2.
For people banking in Denmark, MitID is the login used for bank accounts, public services and signing documents. The Agency for Societal Security said MitID codes and passwords should never be shared with callers or senders claiming to represent authorities. Earlier cases have shown how CPR data can circulate, including a former student who went on trial for selling CPR numbers to criminals.
What is not yet known is which company’s access was misused, how long the unauthorized searches ran, or whether the data has been distributed further. Those questions were part of what the National Unit for Special Crime said it would investigate. The register-insight tool at registerindsigt.cpr.dk remains the official route for checking which companies can look up your data.






