
Denmark CPR Register Breach Accessed 8.8M Records via Unmonitored Private Company Account
A private Danish company's CPR access credentials enabled bulk extraction of 8.8 million records, exposing systemic weaknesses in registry oversight. Official responses focus on citizen precautions while procurement and audit gaps remain unaddressed. Independent verification of scope and actor identity is still pending.
The breach occurred through automated bulk queries against Denmark's Central Person Register via a small private company's account, which retained broad access rights under 2023 regulations. Register staff detected anomalous activity on October 2 after roughly 8.8 million records were touched, including many for people with name-and-address protection. The ministry halted the account and notified Datatilsynet, but has not disclosed the firm's identity, contract terms, or logging granularity that allowed sustained access without earlier flags.
Procurement patterns show multiple Danish agencies grant private entities CPR lookup privileges with minimal ongoing audit requirements, mirroring earlier incidents in Sweden's SPAR system where similar contractor access led to prolonged data exfiltration. No technical attribution evidence has been released, leaving open whether the actor was a state-linked group, criminal syndicate, or insider. Official statements emphasize user vigilance while remaining silent on systemic access controls.
The incident reveals a recurring failure mode: governments outsource population registry queries to commercial entities under broad legal authority, then rely on post-breach notifications rather than real-time anomaly detection. With 4 in 5 of the register's 11 million entries touched, downstream fraud risks extend beyond Denmark's 5.9 million residents to expatriates and the deceased. Credit warnings and MitID alerts address symptoms, not the underlying data flow architecture.
Datatilsynet has not yet classified the event or issued enforcement. Police investigation remains open with no public timeline for identifying the actor or confirming data retention.
Datatilsynet: Enforcement decision and fine assessment published within 120 days, exceeding 2M EUR threshold.
Sources (3)
- [1]Datatilsynet Notification(https://www.datatilsynet.dk/nyheder/2025/oct/cpr-adgang)
- [2]Digitaliseringsministeriet Press Release(https://www.digst.dk/nyheder/2025/cpr-brud)
- [3]Ritzau Agency Report via Ministry(https://ritzau.dk/artikel/2025-cpr-access)