Denmark CPR breach: What data was accessed and what should people do?
Unauthorized users accessed names, addresses and CPR identification numbers associated with about 8.8 million people in Denmark’s Central Population Register, the register’s administration said on October 5, 2026. The full range of information accessed has not yet been established. People who may be affected should be alert to messages or calls that use their personal details, avoid sharing login codes or passwords, and follow updates from Danish authorities as the investigation continues.
What officials have confirmed
The Central Population Register, known as CPR, said the unauthorized access involved the legitimate search access held by a private Danish company. The administration has stopped that company’s access and is working with specialists and other authorities to establish what happened. Police are investigating, while Denmark’s data protection authority is examining a notification it received about the incident.
The administration noticed irregular activity on October 2 and said it had occurred during September. The data protection authority said the notification described a very large number of automated searches intended to identify valid CPR numbers. It has not yet reached a conclusion about the precise circumstances or responsibility. Authorities have not identified who carried out the activity.
The figure of approximately 8.8 million does not mean 8.8 million current residents were affected. The register also holds records for people who have moved abroad and people who have died. Officials said their review found that the unauthorized access did not include the names and addresses of people registered for name-and-address protection. That finding should not be taken as confirmation that every other type of information about those people was unaffected.
Which details may be involved?
Names, addresses and CPR numbers are the categories officials have specifically identified, alongside a reference to other information that they have not yet fully described. A CPR number is a personal identifier used across Danish services. Knowing someone’s name, address and identifier could make a fraudulent approach appear more convincing, but access to those details is not, by itself, evidence that a person’s account has been taken over or a loan has been opened in their name.
Authorities have not published a complete account of the fields accessed for each person or confirmed whether the information has subsequently been used for fraud. The investigation could refine both the number of affected records and the description of the data involved. For now, people should not assume that an unexpected caller is genuine simply because the caller knows their CPR number or address.
What people can do now
Denmark’s official digital-safety guidance urges people to be especially cautious about unexpected texts, emails and calls that mention personal information. Rather than following a link in an unsolicited message, contact the organization through a channel you find independently. Do not disclose MitID details, one-time codes, passwords or payment-card information to someone who contacts you unexpectedly, even if they claim to be helping with the breach.
People concerned about identity misuse can consider adding a credit warning to their CPR record through Denmark’s public self-service system. The warning signals to participating lenders that they should take extra care before granting credit in that person’s name. It is not a guarantee against fraud, and it may make a legitimate credit application more difficult. It can be removed when needed. Danish authorities have also made their digital-security cyber hotline available at +45 33 37 00 37 for people seeking advice.
If a person notices an unfamiliar bill, credit application or other sign that their details have been misused, they should contact the relevant business or bank promptly and seek official identity-theft guidance. As officials confirm more about the records involved, the most useful next step will be to check their updates for any instructions specific to affected groups or types of information.

