Denmark Confirms CPR Breach Via Lawful API, 8.8M Records Exposed

Denmark Confirms CPR Breach Via Lawful API, 8.8M Records Exposed
Denmark confirmed a breach of its national identity register (CPR): attackers used a lawful third-party company's valid API credentials to pull names, addresses, and CPR numbers for up to 8.8 million living citizens. Danish agencies are investigating. How the credentials were compromised isn't yet established, and authorities haven't confirmed whether the data has been misused. Because CPR numbers are permanent and used in identity checks across banking and MitID, the impersonation risk is real—but unproven.

On October 5, 2026, Denmark's Ministry of Research, Education and Digitalization confirmed that attackers obtained unauthorized access to the Central Person Register (CPR), pulling names, addresses, and CPR numbers—Denmark's permanent national personal identification number—for roughly 8.8 million living citizens. Authorities treat the exposure as a single breach affecting all registered persons, and the scale of what was actually queried remains under investigation. Minister Christina Egelund called the incident "outwardly serious." Police and the Danish Data Protection Authority (Datatilsynet) have opened an investigation.

The access path

The intrusion began around September, running through a lawful API belonging to an unnamed Danish private company with legitimate rights to query the CPR register. Attackers used that company's authorized credentials rather than exploiting a software flaw. How those credentials were compromised—phishing, stolen keys, insider action, or abuse of legitimate access by the company itself—has not been publicly established. The retrieval ran unchecked for about a month before detection.

Because a CPR number is a permanent identifier—it can't be changed—and is used widely to verify identity across banking, insurance, tax, and citizen-facing services (Borger.dk, MitID), names and addresses paired with CPR numbers lower the barrier to impersonation attempts. What isn't established is whether MitID authentication actually depends on data exposed here or relies on separate factors the leak didn't touch. The identity-theft vector is realistic; its reach into specific services remains unproven.

What's confirmed and what isn't

Authorities confirmed the exposure to the 8.8 million living citizens as a single breach. No perpetrator has been publicly linked to the attack as of the report, and whether the stolen records have been actively misused isn't established. The company's account privileges were revoked after the breach came to light; Datatilsynet has been notified and has launched an audit protocol. No further compromise beyond the initial access window has been reported.

The breakage worth noting

The breach crossed a trust boundary that matters more than a routine credential leak. The CPR register's controls assumed a lawfully integrated party would behave properly—that a registered client only queries records it has a right to query. That assumption failed, and the retrieval ran for roughly a month before detection. Whether the endpoints lacked activity filtering that would have flagged the anomalous request volume, or whether such controls existed but failed to trigger, is not yet established.

What remains open is the scale of what was actually queried versus the register's total population, and who is responsible. Police and Datatilsynet are working to pin down the full access window and what was retrieved. The decisive unknown is whether the attackers stay at exfiltration or start using the data—and how register-side controls get redesigned so a trusted API key can't become a firehose for citizen identity data.