Denmark CPR Data Breach: What Happened and What to Do Now

• Tapovan

On the evening of Friday 2 October 2026, Denmark's CPR administration noticed irregular activity in the national civil registry. Over the weekend it established the scope: unauthorised people had obtained names, addresses and CPR numbers for about 8.8 million registered persons, out of roughly 11 million in the register. The ministry announced this on Monday 5 October. This post explains the Denmark CPR data breach in English for residents, expats and the developers who build systems on top of CPR. It covers what is confirmed, what is only reported and what nobody knows yet, followed by a short checklist of what to do now.

As of 2026-10-06 (official sources and TV 2/DR live coverage last re-checked 5 October, 23:15 Danish time)

  • What: unauthorised access to names, addresses, CPR numbers and other data for about 8.8 million people. The figure covers the living, people who have emigrated, the deceased and others (ufm.dk press release, 5 Oct 2026, in Danish).
  • How: someone misused a private Danish company's lawful access to search the CPR system. The company's access has been stopped.
  • Not included: the names and addresses of people registered with name and address protection.
  • Who did it: unknown. Police are investigating, and the case has been reported to Datatilsynet (the Danish Data Protection Agency).
  • What to do: treat any call, SMS or email that "knows" your details with suspicion. Never share MitID codes, passwords or card details. If you have a concrete suspicion that your CPR number is being misused, consider a credit warning. For help, call the Cyberhotline on +45 33 37 00 37, open 08-24 for now.

Denmark CPR data breach: confirmed vs reported vs unknown

The ministry describes the investigation as being at a preliminary stage and says the figures may still change. The table separates what officials have published from what the press has reported. Items in the "Reported" rows come from interviews and are still developing.

StatusClaimSource
ConfirmedAbout 8.8 million registered persons affected, out of about 11 million in CPR. The ministry says the figure may be "consolidated" as the mapping continues.ufm.dk release
ConfirmedThe data obtained was names, addresses, CPR numbers and other information, limited to what private companies are allowed to access.ufm.dk release
ConfirmedThe method was misuse of a private Danish company's lawful access to search CPR. That access has been stopped.ufm.dk release
ConfirmedThe irregular activity happened during September, was noticed on the evening of Friday 2 October and had its scope established over the weekend. It was announced on 5 October.ufm.dk release
ConfirmedThe incident has been reported to Datatilsynet. Police are investigating together with the relevant authorities.ufm.dk release
ConfirmedThe minister has asked for a thorough security review of the CPR system, and the ministry says initiatives to prevent similar incidents have already been launched.ufm.dk release
Reported (developing)The unauthorised access lasted "about ten days" and involved "an unusually large number of lookups from a small Danish company". The minister also said the security around that company's access "has not been good enough".Minister Christina Egelund via Ritzau / TV 2
Reported (developing)The National Unit for Special Crime (NSK) is investigating with high priority. "A crime has been committed."Vice police inspector Nicklas Fallesen via TV 2
Reported (developing)Digital systems that require MitID, such as your bank, doctor and healthcare services, are not affected.Minister via DR and TV 2
Reported (developing)No lead has been ruled out, including an international dimension.Minister via TV 2
UnknownWho is behind it, what the "irregular behaviour" consisted of, how many times it happened in September, and exactly which CPR numbers were accessed.ufm.dk release; TV 2's list of open questions
UnknownWhether anyone will be given a new CPR number. The minister says it is too early to say.Minister via TV 2 and DR

How a lawful lookup became a breach

Danish companies can legally receive CPR data. Under § 38 of the CPR Act, a business may receive data about "a larger, delimited group of persons" that it has already identified individually, by CPR number, by date of birth and name, or by name and address. It must also have a legal basis under GDPR and the Danish Data Protection Act. The data on offer under § 38(2) includes current name and address (unless protected), date of death, emigration and any credit-warning flag. For more background, see what CPR information is legitimately available.

According to the ministry, the attackers worked inside that channel and misused the company's access "within the scope of the information private companies have access to". That fits the official exclusion of the names and addresses of people with name and address protection, because § 38(2) generally withholds protected names and addresses from private companies.

Am I affected? Assume yes

There is no official way to find out whether your CPR number was leaked. Neither ufm.dk nor sikkerdigital.dk offers a lookup, and no list of the CPR numbers leaked in this incident has been published. The Denmark CPR data breach covers about 8.8 million of roughly 11 million records, including people who have emigrated and people who have died. Aarhus University professor Jens Myrup Pedersen told DR that "you should assume your CPR number has been leaked", because nobody knows exactly which numbers were accessed.

A practical warning from us: be wary of any website, SMS or email offering to "check if your CPR number was leaked". To use one, you would have to hand your CPR number and probably your MitID login to a stranger, which is exactly what scammers want. Official guidance already tells you not to click unexpected links. A leak checker that arrives in your inbox the week after a breach is a phishing lure until proven otherwise.

What to do if your CPR number is leaked: a checklist

The official four-step advice comes from sikkerdigital.dk's incident page (5 Oct 2026, in Danish). We have added MitID's own security rules, which are published in English on mitid.dk.

  1. Be extra sceptical of contact that uses your details. A caller who knows your name, address and CPR number has not proved anything. The ministry's own release says so. Scammers can also spoof caller ID so that the call appears to come from your bank or the police. Hang up, then call the organisation's main number yourself.
  2. Don't click unexpected links. Go to the official website yourself instead.
  3. Never share MitID details, one-time codes, passwords or card details. This includes MitID QR codes, so never send screenshots of them or share your screen while one is showing.
  4. Read every MitID approval. MitID's rule is that if the text doesn't match what you are doing, or you didn't start the action yourself, you should not approve it.
  5. Consider a credit warning, if you have a concrete suspicion that someone is misusing your CPR number. See the next section.
  6. Turn on MitID notifications. MitID can alert you by app, SMS or email about critical events, and you can choose to be notified every time your MitID is used.
  7. If you have already given details away: block your card or MitID, call your bank, report the misuse via politi.dk and call the Cyberhotline.

MitID scam and phishing scripts to expect

sikkerdigital.dk and mitid.dk describe the following patterns. Data from the Denmark CPR data breach makes each of them more convincing, because the scammer can now quote your real address and CPR number. The scripts themselves have not changed.

What you see or hearWhat it really isWhat to do
"This is MitID support, please approve a request so we can secure your account."Fraud. According to MitID, it never contacts you this way.Hang up. If you are unsure, call MitID Support yourself on +45 33 98 00 10.
A call that shows your bank's or the police's number and asks you to move money or confirm codes.Possibly a spoofed number.Hang up and call the bank's main number yourself.
An email or SMS asking for your MitID or one-time code.Fraud. No real company or authority asks for your MitID by email or SMS.Delete it and don't click anything in it.
A message from a "friend" or relative who is stranded abroad and needs money urgently.A classic scam pattern, and one the 2014 podcast below already mentions.Contact the person through a number you already have.
A site offering to "check if your CPR was leaked".No official checker exists.Don't enter your CPR number or MitID.
A call from a hidden, very long or foreign number about your MitID.MitID lists these as red flags.Hang up.

Credit warning in Denmark (kreditadvarsel): who it is for

A credit warning is a flag in CPR that makes it harder for someone to take out loans or credit in your name. It tells banks and companies to take extra care when they check identity. Under § 29(3) of the CPR Act, anyone aged 15 or over can set one. sikkerdigital.dk's advice is that you can create one on concrete suspicion of fraud involving your CPR number ("ved konkret mistanke"), so it is not an instruction for all 8.8 million people. Lenders are not required to check the flag, although sikkerdigital.dk says many companies check the register before granting, for example, a consumer loan. The law sets no expiry date for the flag, so it stays in place until you remove it. According to borger.dk, the flag is registered in CPR immediately, but it can take a few days before it reaches companies' systems. If you later apply for a loan yourself, you can remove the flag first and add it again afterwards. The English version of the official page is Credit warning on lifeindenmark.borger.dk.

This click path is as given by sikkerdigital.dk. The labels are Danish, with English glosses in brackets:

  1. On borger.dk, open the page Kreditadvarsel (credit warning).
  2. In the box Indsæt eller fjern markering om kreditadvarsel i CPR (add or remove a credit-warning flag in CPR), choose Selvbetjening (self-service).
  3. Click Start and log in with MitID.
  4. Choose Opret (create).

To remove the flag later, log in at the same place and delete it. If you cannot use the self-service, borger.dk says your municipality's Borgerservice can help (book an appointment first). The Cyberhotline can also help you create a credit warning.

Name and address protection in Denmark: what it does and doesn't do

According to the release, people registered with name and address protection did not have their names and addresses included. The wording is precise: it excludes their names and addresses, but it does not say their records were left entirely untouched. You apply digitally to your municipality. The protection is registered in CPR immediately and takes effect in other systems the next day, according to Copenhagen Municipality. It lasts one year and can be renewed. The official English guide is Protection of name and address on lifeindenmark.borger.dk. It has limits:

  • Public authorities can still get your address.
  • Credit reference agencies licensed by Datatilsynet may receive a protected name and address under § 38(4) of the CPR Act.
  • Private creditors or others with a legal interest, for example when you are behind on a payment, can still obtain it.

It is a privacy measure for people with a reason to hide where they live. It is not a general response to this breach.

Where to get help

  • Cyberhotline for digital sikkerhed, run by Styrelsen for Samfundssikkerhed: +45 33 37 00 37. It is temporarily open 08-24 "in the coming days". Normal hours are weekdays 08-20 and weekends and public holidays 10-16. There is also a contact form.
  • MitID Support: +45 33 98 00 10. Call it yourself if you have doubts about a MitID request.
  • Police: report misuse via politi.dk.
  • sikkerdigital.dk: the official guidance pages linked throughout this post. They are in Danish.

Is a CPR number a secret? No, it is an identifier

A CPR number is your birth date followed by a four-digit serial. It was designed to tell people apart, not to prove who someone is. For the full background, see what a CPR number is and how it is used. The legal framework treats it the same way. The CPR Act lets businesses receive CPR data in bulk for people they have already identified (§§ 38-39). § 11 of the Danish Data Protection Act lets private parties use it where it is crucial for unique identification, and forbids publishing it without consent. A number that thousands of organisations hold legitimately cannot work as a password.

This also explains why sikkerdigital.dk says it is "difficult to misuse CPR information alone" to buy goods or take out loans online. Historically, only a few identity-theft victims have needed a new CPR number. The real risk is social engineering, where a scammer recites your CPR number to sound official, and weak identity checks that accept "name + address + CPR" as proof.

One detail matters for developers. CPR numbers used to be issued so that they passed a check-digit test known as modulus 11. The CPR office's own 2008 document explains that numbers with a check digit are issued first for each birth date, and numbers without one are issued once those run out. Secondary sources date this practice to 2007. A valid, real CPR number can therefore fail a modulus-11 check, so a check-digit test proves nothing about whether a number is real or belongs to the person in front of you.

Watch: Danes & IT: Anyone can guess your CPR number, from The How to Live in Denmark Podcast

Kay Xander Mellish's short episode is useful background on why Danes use CPR for "everything" and why that worried people long before this breach. Her central point is still correct: CPR is not a secret. The episode first aired in 2014 and was re-uploaded in 2023, so a few details are now out of date.

  • 3:02-4:14: how language once insulated Denmark from cybercrime, the "stranded in Leeds" scam email, and the fear that identity theft was coming.
  • 4:21-4:55: CPR is used for banking, the doctor, school and the library, and "if they don't [have it] it's pretty easy to guess". One correction: at 4:47 the last digits are called "two random numbers". The CPR office describes them as a serial allocated in sequence for each birth date, so they are not random.
  • 5:08-5:20: "anyone who has your CPR can impersonate you". For today's official channels this overstates the risk, because MitID-protected systems are reported as unaffected.
  • 5:31-5:52: NemID and a wish for phone confirmation codes. NemID closed on 31 October 2023 and was replaced by MitID, whose app approvals come close to what she asked for.

Video by How to Live in Denmark: A fun guide to Danish life.

CPR number security for developers and businesses

The Denmark CPR data breach did not need anyone to break the CPR system's cryptography. According to the ministry, it ran through a lawful business access channel. That makes it a useful case study for anyone whose system stores CPR numbers or queries a registry. Nothing below claims to describe how this specific company was compromised, because that has not been disclosed.

1. Never use CPR as authentication

Don't treat a CPR number, or name + address + CPR, as proof of identity. That combination is exactly the data that was obtained. According to TV 2, the Confederation of Danish Industry (DI) said that companies can no longer treat a CPR number as sufficient proof of identity, and it recommends MitID, customer-portal login or other verification. DI's list also includes control questions. If yours ask for registry facts such as a birth date or a previous address, assume the answers have leaked too. Use a real authenticator such as MitID.

2. Least privilege and purpose limitation on registry access

§ 38 already sets a narrow purpose: data about people you have identified individually in advance. Apply the same rule in your own system. Give each integration only the fields it needs, and only for people it has a business reason to look up. If a service account can query anyone at any time, the access is broader than the law intends. In the minister's words (via Ritzau/TV 2), the security around this company's access "has not been good enough".

3. Rate limits and anomaly alerts on bulk lookups

According to the release, the irregular activity ran during September and was noticed on 2 October. Jens Myrup Pedersen told DR that the rule of thumb should be least privilege plus mechanisms that trigger alarms or blocks when there are unusually many lookups. Set a per-account volume cap that matches the real business case. Alert on deviation from each account's normal baseline, and block automatically above a hard ceiling, so that a human decides whether to lift the block. Keep an audit trail of who looked up what, so you can tell afterwards which records a misused account touched. In this incident, that is exactly the question nobody can yet answer.

4. Protect the accounts that already have access

Myrup Pedersen called compromising someone who already has CPR access "an obvious way in". Treat registry credentials like production database credentials. Scope them to one system, rotate them, store them in a secrets manager, require MFA for the people who use them, and monitor how they are used.

5. Minimise and mask CPR numbers

The safest CPR number is one you never stored. If you do need it, keep it out of logs, analytics and support tooling. § 11(3) of the Data Protection Act forbids publishing CPR numbers without consent, and a log file that leaks CPR numbers exposes exactly what that rule protects. See masking CPR numbers in logs and databases for practical patterns.

6. Know your GDPR breach duties

  • Art. 33: notify the supervisory authority (Datatilsynet in Denmark) without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk. You may provide the information in phases, and you must document every breach. A processor must tell its controller without undue delay.
  • Art. 34: if the breach is likely to result in a high risk, tell the affected people in clear and plain language. If individual notice would take disproportionate effort, a public communication can be used instead.
  • Art. 87 and DPA § 11: national ID numbers may be used only under appropriate safeguards. In Denmark, private parties may process CPR numbers only on the grounds listed in § 11(2), such as a legal requirement or consent, or where disclosure is a natural part of normal operations and crucial for unique identification.

The legal texts are on EUR-Lex (GDPR) and retsinformation.dk (Data Protection Act). For how this fits into system design, see GDPR rules for personal identifiers.

FAQ

Is my CPR number leaked? Is there a checker? (cpr lækket)

No official checker exists, and the authorities have not published a list of affected numbers. With about 8.8 million of roughly 11 million records involved in the Denmark CPR data breach, the practical answer is to assume yours is among the leaked CPR numbers (in Danish searches: "lækkede cpr numre"). Treat any third-party leak-check site that asks for your CPR number as a scam risk.

Will I get a new CPR number?

It is too early to say, according to the minister (TV 2, DR). sikkerdigital.dk notes that historically only a few identity-theft victims have needed a new number. The CPR office says numbers are never reused and are normally replaced only if they were assigned incorrectly, for example with the wrong birth date or sex.

Is MitID or my bank affected?

According to the minister, speaking to DR and TV 2, digital systems that require MitID, such as banks, doctors and healthcare, are not affected. The data obtained was names, addresses, CPR numbers and similar information, not MitID credentials. Treat this as a statement made during an ongoing investigation.

Does a credit warning stop all loans in my name?

No. It is a flag that companies may choose to receive and check, but they are not obliged to. sikkerdigital.dk says many companies do check it. The official advice is that you can create one on concrete suspicion of fraud involving your CPR number, and anyone aged 15 or over can set or remove it themselves with MitID.

I'm an expat or I've left Denmark. Am I included?

Possibly. The ministry says the 8.8 million includes people who have emigrated as well as living and deceased persons. The same advice applies: be sceptical of contact that uses your details, and never share MitID codes.

Update log

  • 2026-10-06 (re-check at 23:15 Danish time on 5 October, 21:15 UTC): No new official information. ufm.dk still lists only the 5 October release, with no update note. sikkerdigital.dk's incident page is unchanged. We found no statement on Datatilsynet's news archive or on politi.dk/NSK, and no new TV 2 or DR live entries since the evening of 5 October. The company has still not been named officially, and the official figure is still about 8.8 million. borger.dk now loads again, so we added links to the official credit-warning pages (borger.dk, lifeindenmark) and the name and address protection guide, plus borger.dk's notes on how long a credit warning takes to reach companies and on removing it before you apply for credit yourself.
  • 2026-10-06: First version of this Denmark CPR data breach explainer. Based on the ufm.dk press release (5 Oct 2026), sikkerdigital.dk's incident page (5 Oct 2026), and TV 2 and DR live coverage as of the evening of 5 October, Danish time. At that time we found no further official update on ufm.dk, cpr.dk, politi.dk or Datatilsynet. The Cyberhotline's 08-24 hours are a temporary extension; its normal hours are weekdays 08-20 and weekends and holidays 10-16.

Main sources: ufm.dk, sikkerdigital.dk, CPR Act (LBK 1010/2023), mitid.dk scam calls, TV 2 live, DR live.

Last updated: 2026-10-06; facts last re-checked against official pages and TV 2/DR coverage on 5 October 2026 at 23:15 Danish time. This is a developing story.

Last updated: October 06, 2026
an "open and free" initiative. Powered by Blogger.