EU cybersecurity

Denmark's CPR Breach Shows a Lifelong Identifier Is Only as Safe as Its Least Careful Authorised User

Attackers used a Danish firm's legitimate access to the CPR register to expose 8.8 million people, and the weak point was access governance rather than a hack of the core system.

Denmark CPR Breach at a Glance People of Internet Research · EU ~8.8M People exposed Names, addresses and CPR numbers w… ~11M Records in register Includes residents, emigrants and … Oct 2024 NIS2 transposition deadline Member States were due to transpos… peopleofinternet.com
Denmark CPR Breach at a Glance People of Internet Research · EU ~8.8M People exposed ~11M Records in register Oct 2024 NIS2 transposition de… peopleofinternet.com

Key Takeaways

Denmark is investigating a breach of its Central Person Register (CPR) that exposed the names, addresses and 10-digit CPR numbers of about 8.8 million people. The government announced it on Monday, October 5, 2026. According to The Record, the perpetrators exploited an unnamed domestic company's legitimate access to the register. They carried out unauthorized searches during September. Minister Christina Egelund called it "a deeply serious incident" and ordered a broad security review.

What happened, and what did not

This was not, on the facts reported so far, a break-in against the register's core infrastructure. The attackers used credentials and access that the state had granted to a private company. Officials first detected irregular activity on Friday. Investigators concluded over the weekend that the breach took place during September. Denmark's Data Protection Agency says it was notified on Sunday.

The register holds records on around 11 million people, including residents, people who have moved abroad, and the deceased. Denmark's population is just over six million. About 8.8 million records is therefore roughly four in five of everything the register holds. The exposed fields are the ones that matter most. A CPR number begins with the holder's date of birth and is used for healthcare, banking and government services. It is designed to last a lifetime.

That last point is the core of the harm. A leaked password can be changed. A leaked lifelong identifier cannot, and the CPR number is widely treated as a semi-public lookup key. Its exposure creates a durable risk of impersonation and social-engineering fraud, and of targeted phishing that uses correct names, addresses and birth dates.

The strongest case for tougher rules

Regulators and privacy advocates will make a serious argument, and it deserves a fair statement. Governments compel citizens to hold these identifiers and cannot offer an opt-out. A state that creates a single national key and then lets hundreds of private firms query it carries a special duty of care. On that view, strict liability, mandatory penalties and sweeping new access limits are justified. Denmark has also been here before. In 2015 the State Serum Institute sent data on more than five million people, on unencrypted CDs, to a Chinese visa centre. In 2016, Altinget reported that the Danish government intended to exempt public authorities from GDPR fines. Critics said that removed the incentive to invest in security.

The EU framework already leans this way. The European Data Protection Board's Guidelines 9/2022 on personal data breach notification, adopted in final form on April 4, 2023, set out how controllers should assess and report breaches under the GDPR. The NIS2 Directive extended cybersecurity duties to public administration at central and regional levels. Member States were due to transpose it by October 17, 2024.

Where proportionality matters

The lesson here is narrower than "more regulation", and it is more useful. The reported failure was in access governance: who may query a national register, at what volume, and with what monitoring. Several measures address that directly, and none of them requires a new law.

Blunt responses carry costs. Banning private-sector access to the register would break legitimate services such as credit checks, healthcare administration and address verification. It would also push firms toward worse, less accountable data sources. Disproportionate liability on small access-holders may deter them from holding data at all, while doing little about the state's own monitoring gaps. The company whose access was abused should be examined, but responsibility is shared. The state decided who gets access and what the access allows.

What to watch

Three questions will decide whether Denmark's response is credible. Will the security review be published, so that other EU administrations can learn from it? Will the Danish Data Protection Agency treat the state as a controller with the same exposure as a private firm? And will the government address the dependence on the CPR number as proof of identity, or only tighten the register's front door?

The Record notes that the breach is the most significant CPR incident since 2015. That is the wrong benchmark. The 2015 incident was a handling mistake involving physical media. This one shows that a well-run, widely trusted digital register can be drained through its own approved channels. Other EU member states that run population registers, or are building digital identity wallets, should be asking the same questions now.

The pro-innovation position is neither to freeze access nor to shrug. Digital public infrastructure works because many parties can build on it. Making that safe means treating every authorised user as a potential point of compromise and monitoring the register accordingly.

Sources & Citations

  1. The Record: Data breach at Denmark's national population register
  2. European Commission: NIS2 Directive
  3. EDPB Guidelines 9/2022 on personal data breach notification
  4. Altinget: Regeringen vil ikke straffe offentligt CPR-sjusk (2016)