Back
CPR data accessed without authorization for about 8.8 million people
SiTech AI Team1 min read

CPR data accessed without authorization for about 8.8 million people

Denmark's CPR administration says an unauthorized party abused a company's legitimate system access, reaching records for about 8.8 million people. Protected names and addresses were not accessed.

Scope of the security incident

Det Centrale Personregister, Denmark's Central Person Register, reported on 5 October 2026 that it had detected a serious security incident. An unauthorized party misused a Danish company's legitimate access to search the CPR system and gained access to citizen information.

The information included names, addresses, CPR numbers and other listed data. It concerned approximately 8.8 million people registered in the CPR system. The unauthorized party reached the information by misusing the company's lawful system access.

Name and address protection

The CPR administration's review found that the unauthorized access did not include names or addresses belonging to people who had registered with name and address protection. The announcement specifically excludes those two categories for protected people but provides no further detail about the treatment of their other information.

Response and investigation

The CPR administration stopped the company's access after detecting the incident. It is working with specialists and authorities to establish the sequence of events. The administration has also notified Datatilsynet, Denmark's data protection authority.

The police are investigating the incident in cooperation with relevant authorities. The case remains under investigation, with the review focused on how the company's legitimate access was misused and which records were reached.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.