Denmark CPR Breach Misused Company Access
Denmark’s CPR administration says lawful company search access was misused to obtain permitted data for about 8.8 million registered people.
Registered people include living residents, people abroad and deceased people. The figure is not a count of confirmed fraud victims.
What officials know
The activity occurred in September. Officials detected it on 2 October, blocked company access and involved police. Protected names and addresses were excluded.
The regulator says it received notice on 4 October. Reported mass automated lookups sought valid CPR numbers. It is examining what happened and responsibility for processing.
What readers should do
The ministry warns that genuine details make contact convincing. Do not disclose passwords or confidential information because someone knows your name, address or CPR number.
Neither notice names the company or actor, confirms motive, details every person’s exposed fields, establishes onward use or fraud, or closes the investigation.
Sources: Danish ministry notice, 5 October 2026; Danish Data Protection Agency, 5 October 2026.


