Privacy Unpacked

SecurityQ&A

CPR Breach Exposes 8.8 Million Danes: What to Do Now

8.8 million CPR records were exposed in Denmark. Learn what was taken and your first steps: register a credit warning and avoid scams.

By Mira Jensen, Reporter · Fact-checked by Theo · Approved by Vera Dunkelten · Published 9 October 2026

AI-assisted: researched and drafted with AI, checked against the sources linked below, and read by our editor. How we work

A four-step flow shows a leaking ID card with a CPR-style number, an arrow to a hand filling out a credit-warning registration form, an arrow to a crossed-out telephone handset representing a suspicious call, and a final arrow to a bank statement being checked off, illustrating the recommended steps after the Danish CPR data breach.
Illustration

Denmark's Central Person Register (CPR) office confirmed a breach exposing names, addresses and CPR numbers for about 8.8 million people. The unauthorized access happened in September 2026 and was discovered on October 2, according to TechCrunch. If you are registered in Denmark, living or emigrated, here is what to do first and what is known so far.

What should I do right now if I'm registered in Denmark?

  1. Register a credit warning (kreditadvarsel) through borger.dk or at your local Borgerservice office. A credit warning "makes it harder for someone to obtain loans or credit in another person's name" and tells companies to run extra identity checks before approving applications, according to The Copenhagen Post. Nearly 970,000 people had registered one by October 7, up from under 250,000 a week earlier.
  2. Treat calls, texts and emails that already know your CPR number or address as suspicious, not reassuring. Having your correct details is no longer proof that a caller is legitimate. Danish minister Christina Egelund has said the breach "allowed hackers to steal names, addresses, Danish social security numbers, and other information," per TechCrunch — exactly the details a scammer would use to sound authentic.
  3. Never share MitID codes, one-time codes, or passwords with anyone who contacts you, even if they reference your CPR number to sound official.
  4. Watch your accounts and mail for loans, subscriptions or credit lines you did not open. A credit warning helps, but checking statements yourself closes the gap before a warning is registered.
  5. If you have specific reason to suspect fraud already, Denmark's Agency for Societal Security has specifically recommended registering a warning in that situation, according to The Copenhagen Post.
  6. Where a service lets you choose, log in with MitID or a one-time code rather than a password alone.

What exactly was taken in the breach?

The CPR office's official notice states that unauthorized parties obtained names, addresses, CPR numbers and more for roughly 8.8 million registered people, living and deceased — the Danish equivalent of Social Security numbers, as SecurityWeek notes, confirmed by register staff over the weekend following the breach's discovery.

Who is affected, and why 8.8 million?

CPR holds records on about 11 million people total, including residents, emigrants and the deceased, a system established in 1968, per SecurityWeek. Of those, roughly 8.8 million had their data exposed. People registered with name and address protection were not affected, according to the CPR office's official notice. CSO Online reports that the compromised company account was used for more than 14 million searches, of which about 8.8 million actually returned records.

How did the attackers get the data?

According to TechCrunch, the Danish government said unauthorized access was obtained by "abusing a Danish company's lawful access to search for information in the CPR system." The Copenhagen Post reports this abuse ran for about 10 days in September, and was discovered after the company received an unusually large bill, since each register search carries a fee. CPR's access for that company has since been cut off, the case was reported to the Danish Data Protection Agency (Datatilsynet), and police are investigating alongside other authorities, per the CPR office's official notice. CSO Online adds that Denmark's National Special Crime Unit is investigating and that a broader security review of the CPR system is now underway.

What is still unknown?

The company involved has not been named publicly, and "the company has not been identified, and authorities do not know who was responsible," per The Copenhagen Post. SecurityWeek reports that CPR said it would review its security policies and improve protections to prevent similar incidents, and that it could not name the threat actor behind the breach. No source confirms whether the stolen data has been sold or published anywhere, and the exact data fields taken per individual record have not been detailed beyond names, addresses and CPR numbers. TechCrunch notes the breach "is thought to be the biggest in the country's history," drawing comparisons to earlier breaches of national ID databases in Turkey and India.

Can my CPR number be changed, and can the stolen data bypass MitID?

Digitalisation minister Christina Egelund "said it remained too early to determine whether affected people would need new CPR numbers, which are Denmark's personal identification numbers," according to The Copenhagen Post, so no decision has been made on reissuing numbers. On MitID specifically, CSO Online reports that "officials are advising organizations not to rely on a CPR number alone and to use stronger mechanisms such as MitID, two-factor authentication, or one-time codes." Related reading: what end-to-end encryption protects.

Sources

  1. The Copenhagen Post cphpost.dk
  2. TechCrunch techcrunch.com
  3. official notice cpr.dk
  4. SecurityWeek securityweek.com
  5. CSO Online csoonline.com