Free guide: How to use AI in compliance
← Back

The CPR data breach: 8.8 million Danish records taken through one company's lawful access

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published October 5, 2026Reviewed by Charlene Wang
Editorial illustration for the article "The CPR data breach: 8.8 million Danish records taken through one company's lawful access".

Denmark's CPR data breach exposed names, addresses and CPR numbers of 8.8 million people through a company's lawful lookup access. What it means for KYC teams.

Table of contents

The CPR data breach exposed the names, addresses and CPR numbers of about 8.8 million people registered in Denmark's Central Person Register. Nobody broke into the register itself. Unauthorised parties misused a private Danish company's lawful access to search it during September 2026, the digitalisation ministry said on 5 October.

  • About 8.8 million registered persons are affected, including living, emigrated and deceased people, out of roughly 11 million records in the CPR system.
  • The data obtained includes names, addresses and CPR numbers. People registered with name and address protection were not included.
  • The misused access belonged to an unnamed private company and has been stopped.
  • The CPR administration has notified Datatilsynet, the police are investigating, and the minister has ordered a thorough security review of the CPR system.
  • Danish AML rules make the CPR number a core identity data point, so knowing one can no longer count as evidence of who a customer is.

What happened in the CPR data breach?

Unauthorised parties used a Danish company's lawful search access to pull name, address and CPR number data on about 8.8 million people. The CPR administration noticed irregular activity on the evening of Friday 2 October 2026. The activity had taken place during September, and the ministry announced the incident on 5 October.

The announcement came from the Ministry of Research, Education and Digitalisation, which runs the CPR administration. Its press release of 5 October 2026 states that the access happened by misusing "en dansk virksomheds lovlige adgang" (a Danish company's lawful access) to search the system. The ministry stresses that the access stayed within the categories of data that private companies are allowed to receive.

Minister Christina Egelund called it "en dybt alvorlig hændelse" (a deeply serious incident) and has briefed the parliament's business and digitalisation committee. The ministry has not named the company and says it cannot yet say who is behind the incident.

ItemDetail
RegisterDet Centrale Personregister (CPR), Denmark's civil registration system
Records affectedAbout 8.8 million registered persons
Total in registerAbout 11 million, including deceased and emigrated people
Data obtainedNames, addresses, CPR numbers and other details
ExcludedPeople registered with name and address protection
Access routeA private Danish company's lawful search access
Activity periodSeptember 2026
DetectedEvening of 2 October 2026
Announced5 October 2026
Response so farAccess stopped, Datatilsynet notified, police investigating, security review ordered

How could lawful access expose 8.8 million records?

Section 38 of the CPR Act lets private companies with a legitimate interest receive register data on a large, defined group of people they have already identified one by one. The ministry cites this right but has not said which route the CPR data breach used.

The safeguard sits on the input side: a company must already hold an identifier for each person. Under section 38(5) of the consolidated CPR Act, each person must be identified by CPR number, by date of birth and name, or by address and name. Section 38(6) adds that the company must be entitled to process the data under the GDPR and the Danish Data Protection Act. Section 38(2) lists what may then be returned, including current name and address, date of moving there, death, disappearance, emigration and any marketing or credit-warning flags. Names and addresses under protection are withheld, which matches the ministry's statement that protected people were not included.

Access typeLegal basisWho may use itIdentification required
Bulk delivery on a defined groupCPR Act section 38Companies and traders with a legitimate interestCPR number, or date of birth and name, or address and name
Single electronic lookupsCPR Act section 39 with section 42Companies and traders, associations with a recognised purposeName plus date of birth, address or CPR number
Credit reference bureausCPR Act section 38(4)Bureaus licensed by Datatilsynet, which also receive protected names and addressesCPR number, or date of birth and name, or address and name

The design assumes that the input identifiers act as a brake on scale. A list of 8.8 million records suggests that brake did not hold, either because the attackers already held large identifier lists or because the company's access allowed something wider than one person at a time. The ministry has not said which.

What does the CPR data breach mean for KYC and AML obligations?

The CPR data breach does not change any Danish or EU rule today, but it weakens one input every Danish onboarding flow depends on. When names, addresses and CPR numbers for most of the register are in unauthorised hands, a customer who simply knows those details has proved nothing.

Customer due diligence under the Danish AML Act. Section 11(1)(1)(a) of the hvidvaskloven requires identity data for a natural person to include name and CPR number. Section 11(1)(2) then requires firms to verify that data against documents, data or information from a reliable and independent source, and names electronic identification means as an example.

The breach does not touch the first duty. It does, however, raise the bar for the second: a check that only confirms a submitted name, address and CPR number match the register now confirms data that may be stolen. Verification should rest on something the fraudster cannot copy from a list, such as MitID or another electronic identification means, or a document whose chip can be read.

Suspicious activity reporting. Section 26 of the same Act requires firms to notify the Hvidvasksekretariatet immediately when they know, suspect or have reasonable grounds to suspect a link to money laundering or terrorist financing. It explicitly covers attempted transactions and approaches from possible customers. Applications that pair correct CPR data with mismatched contact details, new devices or mule-like activity after September 2026 belong in that assessment.

The EU AML Regulation from 10 July 2027. Article 22(1)(a) of Regulation (EU) 2024/1624 lists the national identification number, where applicable, among the data firms must obtain. Article 22(6) then allows verification either by an identity document plus, where relevant, reliable and independent sources, or by electronic identification meeting the eIDAS "substantial" or "high" levels and relevant qualified trust services. The CPR data breach is a concrete reason to weight the second route, and the document route with a chip read, over a register match alone.

Data protection duties for CPR users. Section 11(2) of the Danish Data Protection Act allows private companies to process CPR numbers only on listed grounds, such as a legal requirement or consent, and section 11(3) bars publishing them without consent. Every firm with section 38 or section 39 access is also a controller for the register data it receives, and GDPR Article 32 requires security appropriate to the risk.

Fraud controls on account recovery. The ministry warns people never to hand over passwords, even when a caller appears to know their name, address and CPR number. Firms that use those three facts to authenticate callers or reset credentials should treat that method as compromised by the CPR data breach. Our glossary entries on vishing and account takeover cover the typical pattern.

What is still uncertain about the CPR data breach?

The core facts are confirmed, but the mechanism, the actor and the full data scope are not. The ministry states that its findings may be consolidated as the investigation continues. Four open questions matter most to compliance teams deciding how much to change now.

How CPR numbers were obtained. Section 38(2) of the consolidated CPR Act lists the data a private company may receive, and the personal identification number itself is not on that list. The ministry nonetheless says CPR numbers were obtained, while also saying the access stayed within what private companies may receive. Either the attackers supplied CPR numbers as input and harvested the linked data, or the company's access returned more than the core list suggests. The answer decides whether this is a control failure at one company or a design gap in the access regime.

Which company, and what it held. The ministry has not named the company. Until it does, firms cannot tell whether a vendor they use for address checks or CPR lookups is involved. That leaves a third-party risk question open for every Danish obliged entity that buys register data through an intermediary.

Liability between the register and the user. The CPR administration controls the register. The company was a lawful recipient. The attackers were neither. How Datatilsynet allocates responsibility between a public register operator and a private access holder will shape what access controls the state demands of every section 38 user.

The cost of tighter access. The minister has ordered a thorough security review and says: "Vi har allerede iværksat initiativer i forhold til CPR, der skal forhindre lignende hændelser" (we have already launched initiatives on CPR to prevent similar incidents). Banks, insurers, debt collectors and landlords rely on CPR lookups for address updates and identity checks. Tighter rate limits, logging or vetting would add friction for those lawful users. The scope and timing of any change are not yet known.

How does this compare with recent identity data breaches?

By people confirmed affected, the CPR data breach is larger than each of the recent identity breaches below, and it is the only one involving a national population register. It also follows a pattern already seen at Revolut and AssuranceAmerica: misused legitimate access was the way in.

IncidentDate disclosedPeople affectedRoute inData
Danish CPR register5 Oct 2026About 8.8 millionMisused lawful company accessNames, addresses, CPR numbers
Times Car, JapanSep 2026About 6.6 million accounts, 1.6 million ID imagesSystem intrusionAccount data, ID document images
AssuranceAmerica, USJul 20266,998,886Compromised employee credentialsNames, contact details, driver's licence numbers
RevolutSep 2026Not disclosed, described as limitedForged government requestID documents, contact details
IDScan.net, USSep 2026153 million scans advertised, unconfirmedUnder investigationID scans

The figures come from our earlier coverage of the Times Car breach, the AssuranceAmerica breach, the Revolut disclosure and the IDScan incident. The running list sits in our KYC and IDV breach tracker.

The difference is reach. A company breach exposes its own customers. The CPR data breach exposes most of the register that every Danish firm draws its customers' identity data from, so the fraud risk lands on firms that did nothing wrong.

How should compliance teams respond?

Treat name, address and CPR number as public for authentication purposes, and lean harder on verification that cannot be replayed from a list. None of this needs to wait for the ministry's final findings. The steps below cover onboarding, account recovery, vendors and monitoring, in that order.

Start with onboarding. Review any Danish flow where a register match on name, address and CPR number is the main verification step, and require electronic identification such as MitID or a chip-read document check instead. Record the change in your business-wide risk assessment, citing the CPR data breach as the trigger.

Next, remove CPR number knowledge as a factor in call-centre authentication and password resets, and route unusual recovery attempts on Danish customers to fraud review.

Then check your supply chain. List every vendor that performs CPR lookups for you under section 38 or section 39. Ask each whether it is the company concerned, what logging and rate limits it applies, and how it would notify you. Recheck the lawful basis for any CPR numbers you hold under section 11 of the Data Protection Act, and delete what you do not need.

Finally, tune monitoring. Watch for applications that combine correct Danish register data with new devices, new contact details or rapid fund movement, and assess them for a section 26 report.

Zyphe verifies identity by reading the NFC chip of a passport or ID card to ICAO 9303 standards with two-step liveness, so knowing someone's name, address and CPR number is not enough to pass. After verification, the data is encrypted into the user's own vault and sharded across a network of thousands of nodes, so there is no central store of customer PII to misuse; see how vault-based PII storage works, or book a demo.

The bottom line

The CPR data breach is a warning about access, not just about hacking. A lawful lookup channel became a way to collect data on most of the register that Danish firms onboard from. For KYC teams, the practical lesson is to stop treating knowledge of identity data as proof of identity, and to anchor verification in something that cannot be copied from a list.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

The ministry says unauthorised parties obtained names, addresses and CPR numbers, among other details, for about 8.8 million registered persons. Anyone registered with name and address protection was not included. The ministry warns that details may be refined as its investigation continues.

Not in the usual sense. The ministry says the attackers misused a private Danish company's lawful access to search the register, and that the access stayed within the categories of data private companies may receive. The company's access has been stopped. The police are investigating, and the ministry says it cannot yet say who is behind the incident.

Yes. Section 11 of the Danish AML Act still requires a natural person's identity data to include name and CPR number. What changes is the weight of a match. Because the numbers are now in unauthorised hands, a matching CPR number shows the data is correct, not that the applicant is the person it belongs to, so firms should verify through electronic identification or a document check.

The ministry advises people never to hand over passwords or other confidential information over the phone or by email, even when the caller seems to know their name, address and CPR number. It points people to sikkerdigital.dk and to the Cyberhotline for digital security, which has extended its opening hours to 8:00 to 24:00 in the coming days.

From 10 July 2027, Article 22 of Regulation (EU) 2024/1624 requires firms to obtain the national identification number where applicable. Verification must then rely on an identity document with reliable sources, or on electronic identification at the eIDAS substantial or high level with relevant qualified trust services. A register match on its own is not one of the listed routes.

See privacy-first KYC in action

Verify identity without a central store of documents. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo