Danish CPR Breach Exposes 8.8 Million Records via Corporate Credential Abuse
A commercial account compromise exposed core identity data for 8.8 million Danish citizens. The breach underscores systemic risks when AI pipelines rely on centralized population registers without granular access controls. Operational fixes will likely include mandatory audit trails and revocation of broad commercial query rights.
Det Centrale Personregister confirmed the incident occurred through misuse of an authorized commercial query interface. Attackers extracted core identity fields but did not reach records protected by name-and-address shielding. CPR administration immediately revoked the company's access and notified Datatilsynet plus police investigators.
Registry logs show the intrusion spanned multiple months before detection. The 8.8 million figure covers nearly the entire Danish population plus some non-residents. No evidence indicates bulk export of shielded data or direct exfiltration of protected attributes.
This event follows documented patterns of credential chaining in Nordic government registries, where commercial intermediaries become single points of failure. As AI systems increasingly ingest public-sector identity data for training or verification, such exposures create durable attack surfaces that persist beyond any single breach notification.
Investigation outcomes will determine liability under GDPR Article 32 and potential administrative fines. Regulators are expected to mandate stricter API logging and zero-trust segmentation for all commercial CPR access within six months.
Datatilsynet: Administrative fine above 15 million DKK issued to involved commercial entity within 9 months.
Sources (3)
- [1]Primary Source(https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger)
- [2]Supporting Source(https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger)
- [3]Supporting Source(https://www.datatilsynet.dk/nyheder/2025/feb/vejledning-til-api-sikkerhed)