Threat reportData BreachTL-2026-3266

Danish CPR Central Register of Persons Breach via Abuse of a Private Company's Legitimate Access (Supply Chain)

highACTIVE

Danish CPR Central Register of Persons Breach via Abuse of a (TL-2026-3266), also tracked as Danish CPR breach, is a high-severity data breach, first published 2026-10-10. It has no confirmed attribution, affects Danish Ministry of Research, Education and Digitalisation (CPR, maps to 5 MITRE ATT&CK techniques (T1078, T1119, T1199), and is covered by 9 detection rules and 6 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
6Indicators of compromise

Key facts for TL-2026-3266

Threat ID
TL-2026-3266
Also known as
Danish CPR breach, CPR register data leak
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, public administration
Target regions
Europe, denmark, greenland
Detection rules
9
Indicators of compromise
6

How Danish CPR Central Register of Persons Breach via Abuse of a works

An unauthorized party abused the legitimate CPR access of a small, unnamed private Danish company to run roughly 14 million lookups over about ten days in September 2026, exposing names, addresses and 10-digit CPR numbers of approximately 8.8 million people. The activity was noticed on 2 October 2026 via an anomalous invoice and announced by the Ministry on 5 October 2026.

Denmark's Central Register of Persons (CPR) holds records on about 11 million people (living residents, emigrants and the deceased) against a resident population of roughly 6 million. Under section 38 of the Civil Registration System Act, private companies with a justified interest may be granted access to look up specified groups of individuals. In September 2026 an unauthorized party abused the access of one such small private Danish company. Reporting describes the attackers as staying within the standard retrieval parameters available to authorized businesses rather than breaching the CPR system itself.

According to reporting citing the CPR administration, about 14 million lookup attempts were made over roughly ten days, of which about 8.8 million returned records. The anomaly was surfaced when the CPR administration billed the company on the evening of Friday 2 October 2026 and the invoice reflected a very large volume of activity; the administration also reported irregular behavior in the system during September. Over the following weekend the extent of access was established, the National Unit for Special Crime visited the company on Saturday evening, and the Danish Data Protection Agency (Datatilsynet) was notified on Sunday 4 October. The Ministry of Research, Education and Digitalisation publicly announced the incident on 5 October 2026.

Exposed data comprises names, addresses and 10-digit CPR numbers (some reporting also cites dates of birth, marital status and family relations). Records of people with name and address protection were reported as not affected. Reporting indicates the register includes more than 55,000 records for Greenland residents. The CPR administration blocked the company's access, a security review was ordered with no stated deadline, and police are investigating and contacting international counterparts. The compromised company has not been named, no suspect or threat actor has been identified, and officials said it was too early to say who is behind it. The exact means by which the company's access was compromised (stolen credentials, insider abuse, or intrusion) has not been publicly disclosed.

The Minister stated it was too soon to say whether all-new CPR numbers would be issued, and organizations were instructed to stop accepting a CPR number alone as proof of identity. Authorities and commentators warned of downstream phishing and identity-fraud risk. The case illustrates third-party and supplier-access risk: a legitimate, low-privilege-looking integration with unrestricted lookup volume enabled near-complete harvest of a national identity register.

MITRE ATT&CK techniques used in TL-2026-3266

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship

Defense Evasion

T1078 Valid Accounts

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Danish CPR Central Register of Persons Breach via Abuse of a

  • Danish Ministry of Research, Education and Digitalisation (CPR administration) — Central Register of Persons (CPR)
    Vulnerable versions: Supplier lookup access under section 38 of the CPR Act, September 2026
    Fixed in: Affected company's access revoked; security review ongoing

Remediation for Danish CPR Central Register of Persons Breach via Abuse of a

Immediate actions

  • Revoke or suspend third-party CPR access for any supplier showing anomalous lookup volume (already done for the affected company)
  • Stop accepting a CPR number alone as proof of identity; require additional authentication
  • Warn citizens and customers about phishing and identity-fraud attempts that use leaked personal data
  • Review CPR lookup logs and billing records for unusual volume or off-pattern search behavior

Workarounds

  • Citizens should use unique passwords, verify unexpected requests through official channels and monitor their accounts

Longer-term hardening

  • Strictly limit what external partners are permitted to view and query
  • Implement per-partner rate limiting, volume caps and baseline-behavior analytics on register lookups
  • Add stronger authentication and shorter sessions for supplier access
  • Monitor continuously for unusual search patterns rather than relying on invoicing to surface anomalies
  • Complete the ministry-ordered security review of the CPR access model

Weaknesses (CWE) in Danish CPR Central Register of Persons Breach via Abuse of a

CWE-285, CWE-770

Timeline of Danish CPR Central Register of Persons Breach via Abuse of a

  • Unauthorized party begins abusing a small private Danish company's legitimate CPR access during September 2026; reporting describes roughly ten days of activity (exact start date not published).
  • Irregular CPR activity during September totals about 14 million lookups, of which about 8.8 million returned records (exact end date not published; month-end used as the latest bound).
  • On Friday evening the CPR administration notices irregular activity, surfaced when the company's invoice reflected a very large volume of lookups.
  • On Saturday evening the National Unit for Special Crime visits the company; the extent of the unauthorized access is established over the weekend.
  • CPR administration notifies the Danish Data Protection Agency (Datatilsynet); the company's access is blocked.
  • Ministry of Research, Education and Digitalisation publicly announces the breach affecting about 8.8 million people and informs Parliament's Business and Digitalisation Committee.
  • Minister Christina Egelund says it is too soon to say whether new CPR numbers will be issued; organizations are told to stop accepting a CPR number alone as proof of identity; police contact international counterparts, with no suspect identified.
  • Infosecurity Magazine publishes expert commentary on supply-chain risk, urging strict limits on external partner views, rate limiting and baseline behavior analysis.

Sources cited for Danish CPR Central Register of Persons Breach via Abuse of a

Detection coverage for TL-2026-3266

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3266 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
6 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats