# Danish CPR Central Register of Persons Breach via Abuse of a Private Company's Legitimate Access (Supply Chain)

> An unauthorized party abused the legitimate CPR access of a small, unnamed private Danish company to run roughly 14 million lookups over about ten days in September 2026, exposing names, addresses and 10-digit CPR numbers of approximately 8.8 million people. The activity was noticed on 2 October 2026 via an anomalous invoice and announced by the Ministry on 5 October 2026.

- **Published:** 2026-10-10T14:22:55Z
- **Last reviewed:** 2026-10-10T14:22:55Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3266
- **ID:** TL-2026-3266
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Denmark's Central Register of Persons (CPR) holds records on about 11 million people (living residents, emigrants and the deceased) against a resident population of roughly 6 million. Under section 38 of the Civil Registration System Act, private companies with a justified interest may be granted access to look up specified groups of individuals. In September 2026 an unauthorized party abused the access of one such small private Danish company. Reporting describes the attackers as staying within the standard retrieval parameters available to authorized businesses rather than breaching the CPR system itself.

According to reporting citing the CPR administration, about 14 million lookup attempts were made over roughly ten days, of which about 8.8 million returned records. The anomaly was surfaced when the CPR administration billed the company on the evening of Friday 2 October 2026 and the invoice reflected a very large volume of activity; the administration also reported irregular behavior in the system during September. Over the following weekend the extent of access was established, the National Unit for Special Crime visited the company on Saturday evening, and the Danish Data Protection Agency (Datatilsynet) was notified on Sunday 4 October. The Ministry of Research, Education and Digitalisation publicly announced the incident on 5 October 2026.

Exposed data comprises names, addresses and 10-digit CPR numbers (some reporting also cites dates of birth, marital status and family relations). Records of people with name and address protection were reported as not affected. Reporting indicates the register includes more than 55,000 records for Greenland residents. The CPR administration blocked the company's access, a security review was ordered with no stated deadline, and police are investigating and contacting international counterparts. The compromised company has not been named, no suspect or threat actor has been identified, and officials said it was too early to say who is behind it. The exact means by which the company's access was compromised (stolen credentials, insider abuse, or intrusion) has not been publicly disclosed.

The Minister stated it was too soon to say whether all-new CPR numbers would be issued, and organizations were instructed to stop accepting a CPR number alone as proof of identity. Authorities and commentators warned of downstream phishing and identity-fraud risk. The case illustrates third-party and supplier-access risk: a legitimate, low-privilege-looking integration with unrestricted lookup volume enabled near-complete harvest of a national identity register.

## MITRE ATT&CK

- T1199 Trusted Relationship
- T1078 Valid Accounts
- T1078 Valid Accounts
- T1213 Data from Information Repositories
- T1119 Automated Collection
- T1589 Gather Victim Identity Information

## Sources

- [Danish CPR Breach Highlights Challenge of Supply Chain Risk](https://www.infosecurity-magazine.com/news/danish-cpr-breach-supply-chain-risk/)
- [Denmark's CPR breach: 14 million lookups in ten days, found through a bill](https://thenextweb.com/news/denmark-cpr-breach-8-8-million-records)
- [Denmark ID register breach (The Register)](https://www.theregister.com/a/5301307)
- [Data breach at Denmark's population register exposes 8.8 million people](https://www.helpnetsecurity.com/?p=386873)
- [Denmark investigates 'extremely serious' breach of national population register](https://www.computing.co.uk/news/2026/security/denmark-investigates-extremely-serious-breach-of-national-population-register)
- [Insurance Journal: Denmark population register breach](https://www.insurancejournal.com/news/international/2026/10/05/887972.htm)
- [Itdaily - Danish civil registry hacked: 8.8 million people affected](https://itdaily.com/news/security/danish-population-register-hacked/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3266
