The story in brief
- What happened?
- Unauthorised parties misused a private Danish company's lawful access to the Central Person Register. The company's access has been stopped.
- Who does 8.8 million refer to?
- Registered people, including those who are deceased or have moved abroad. It is not a count of current Danish residents or a confirmed count of fraud victims.
- What should people watch for?
- Impersonation that uses real names, addresses or CPR numbers. Do not disclose passwords or confidential information merely because a caller knows those details.
Legitimate access was used without authorisation
Denmark's Ministry of Research, Education and Digitalisation announced on 5 October 2026 that unauthorised parties had obtained access to information concerning around 8.8 million people registered in the Central Person Register, known as CPR.
The ministry describes misuse of a private Danish company's lawful search access. This is not the same as a confirmed break-in to every Danish government system. The company was not named in the statement, and the identity of the people behind the incident was not established.
CPR administrators stopped the company's access, notified the data protection regulator and began investigating with specialists and other authorities. The ministry also announced a security review. These responses do not establish that every copy of accessed data has been recovered.
What was accessed, and what the number includes
The official statement identifies names, addresses and CPR numbers among the information accessed. CPR numbers are personal identifiers, not passwords. Combined with contact details, they can make an impersonation attempt sound convincing.
The registry contains around 11 million registered people, including people who are deceased and people who have left Denmark. The affected figure of around 8.8 million must be read in that context. It is not evidence that 8.8 million people currently living in Denmark have suffered financial loss.
The ministry says names and addresses of people registered with name-and-address protection were not included. That assurance is specifically about those fields. It should not be expanded into a claim that every identifier or other record for protected people was excluded.
- Information named in the official noticeSource-backed
- Names, addresses and CPR numbers concerning around 8.8 million registered people.
- Protected names and addressesSource-backed
- The ministry says these fields were not included for people with name-and-address protection.
- Attacker and technical causeNot established
- Not established in the initial statement. A regulator investigation is underway.
- Passwords, payment cards or medical recordsNot established
- The statements checked do not establish exposure of these categories.
What Denmark's regulator has said
Datatilsynet says it received a notification from the CPR register on 4 October. It describes a very large number of automated searches intended to identify valid CPR numbers.
The regulator says it is examining what happened, how it was possible and who was responsible for processing the personal information. Its initial notice does not reach a finding of liability or announce a final affected-person count.
A confirmed access incident and an unfinished investigation can both be true. An unknown attack mechanism should not be replaced with a speculative claim about malware, an insider or a particular hacking group.
How to handle a convincing impersonation attempt
The ministry's central advice is to withhold passwords and other confidential information even if a caller or message sender appears to know your name, address and CPR number.
Knowing your details is not an identity check. End an unexpected call and reach the organisation using contact details you find independently. Do not use a telephone number or login link supplied in the suspicious message.
- Verify through a separate channelIf a caller says they are from your bank or an authority, contact that organisation yourself. Do not confirm extra identity details to prove you are the person they called.
- Do not approve an unexpected login or paymentA claim that money must be moved to a safe account is a warning sign. Stop and speak to your bank through its official app or independently checked contact details.
- Keep evidence if something seems wrongSave the message, sender details and dates without interacting with attachments. If money or account access is at risk, contact your bank and the relevant authorities promptly.
- Use official Danish adviceThe ministry directs people to sikkerdigital.dk and its Cyberhotline. Check current contact details and opening hours there rather than assuming temporary incident hours are permanent.
Public exposure is a separate issue
A public-data scan cannot check whether your specific CPR record was accessed in this incident. Removing unrelated public listings does not delete a statutory register entry or erase information already obtained by another party.
Limiting unnecessary public contact details can reduce information available for targeting, but it is not proof of protection from registry misuse. Follow the authorities' incident guidance as a separate step.
The CPR disclosure timeline
Irregular registry activity
The ministry says the irregular searches occurred during September.
Administrators become aware
CPR administrators identified irregular behaviour on the evening of 2 October.
Regulator notified
Datatilsynet says it received the register's incident notification on Sunday 4 October.
Public statements issued
The ministry describes the unauthorised access and Datatilsynet confirms its investigation.
How the facts were checked
How the facts were checked
This report is based on the ministry's 5 October statement and Datatilsynet's 5 October notice, checked on 9 October 2026. Their findings are attributed to the issuing authorities and remain subject to the continuing investigation.
No exposed records, attacker material or purported victim databases were accessed for this article.
Questions readers ask
Were 8.8 million current Danish residents affected?
That is not what the official figure means. It counts registered people, including deceased people and those who have emigrated.
Were protected addresses exposed?
The ministry says names and addresses of people registered with name-and-address protection were not included. That statement does not establish that every other field was excluded.
Does knowing my CPR number prove a caller is genuine?
No. The ministry explicitly warns against disclosing confidential information even when someone knows your name, address and CPR number.
Sources
- Omfattende uautoriseret adgang til borgeres CPR-oplysningerDanish Ministry of Research, Education and Digitalisation, 5 October 2026
- Datatilsynet er opmærksom på sag om opslag i CPRDatatilsynet, Danish data protection authority, 5 October 2026
Published 9 October 2026. Sources checked 9 October 2026. Last updated 9 October 2026. We do not link to attacker material.
The short version
The CPR access incident is confirmed, but the 8.8 million figure needs context. Treat personal details as information an impostor may know, not proof of identity. Use official channels and keep the regulator's unfinished investigation separate from speculation.



