International Cyber Expo International Cyber Expo
  • About Us
Monday, 5 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access

by Guru Writer
October 5, 2026
in News
Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access
Share on FacebookShare on Twitter

Personal details belonging to around 8.8 million people have been exposed in a breach of Denmark’s Central Person Register (CPR), after unauthorised parties abused a Danish company’s legitimate access to the national civil registration system, authorities confirmed on Monday.

According to the Ministry of Research, Education and Digitalisation, the compromised information includes names, addresses and CPR numbers, along with other data held in the register. Minister Christina Egelund called it “a deeply serious incident” and said she had briefed the Folketing’s Business and Digitalisation Committee. The company’s access to the system has since been blocked.

“The Danish Ministry of Research, Education and Digitalisation has released a statement regarding a cybersecurity incident affecting a large volume of data subjects,” said Nathan Davies-Webb, Principal Consultant at Acumen Cyber. “Approximately 8.8 million people are impacted, which represents roughly 80% of the ~11 million individuals registered in the system.”

The register covers people currently living in Denmark as well as those who have died or moved abroad. Beyond core identity details, it can hold information on marital status, birth registration, family relationships, membership of the Church of Denmark and legal incapacity, although the ministry has not said exactly which fields were accessed in each case. The initial review indicates that people registered for name and address protection were not affected.

“The exposed data includes names, addresses and CPR numbers, along with a person’s status (living, emigrated, deceased), which provides a helpful basis for social engineering and ID fraud,” Davies-Webb said. “There is limited information on how the data was accessed, although the statement confirms the access came from abuse of a private Danish company’s legitimate access to the system. No attribution has been made public at this stage, so further detail is speculative.”

A universal identifier, exposed

For Simon Pamplin, CTO at Certes, the significance lies in what the CPR number unlocks. “The Danish CPR breach represents something more fundamental than a large-scale data incident,” he said. “The CPR number functions as a universal identifier across Danish society, underpinning access to healthcare, banking, public services, tax administration and legal status. Exposing it for 8.8 million people, encompassing the vast majority of everyone who has ever been registered in Denmark, creates a liability that extends across virtually every system those individuals interact with.”

He added: “CPR numbers combined with names, addresses, marital status and family relationships create a dataset of exceptional depth and permanence. These are not credentials that can be rotated or reset. For the individuals affected, the exposure is indefinite.”

Pamplin also warned that the value of the data goes well beyond everyday fraud. “The scale also means the data carries structural value beyond individual fraud. A dataset covering the near-entirety of Denmark’s registered population is precisely the kind of material that attracts state-level interest, enabling intelligence operations, social mapping and long-term targeting well beyond opportunistic criminal exploitation. Harvest now, decrypt later tactics were built for datasets of exactly this nature and permanence.”

Trusted access as the weak point

The route in has drawn particular attention. “This incident demonstrates the inherent risk of highly centralised national databases when private companies are granted direct access to sensitive records,” said Dray Agha, senior manager, tactical response at Huntress. “A compromised account at a single supplier can bypass an organisation’s core security controls and turn a legitimate connection into a massive data exposure.”

Pamplin agreed that the method was revealing. “The attack vector here is particularly instructive. Unauthorised access was achieved by exploiting a legitimate company’s authorised access to the system. Perimeter controls, authentication layers and access governance were present and functioning. The data was readable to anyone operating within the bounds of that legitimate access, and that readability was the vulnerability.”

Jamie Akhtar, CEO and Co-founder of CyberSmart, said: “The breach of Denmark’s Central Person Register has exposed names, addresses and personal identification numbers belonging to around 8.8 million people, including those who have died or emigrated. According to reports, attackers exploited a private company’s legitimate access to the register.”

“This highlights how access granted to third parties can become a route to sensitive information, with exposed personal details potentially helping criminals impersonate individuals or make scams more convincing,” Akhtar continued.

Questions over detection

The ministry says the activity took place during September, and that the CPR administration only became aware of it on Friday evening last week. Davies-Webb pointed to this gap.

“There is an interesting section in the statement in the most recent statement which suggests there may have been a delay in detection: ‘On the evening of Friday 2 October 2026, the CPR administration became aware that there had been irregular behaviour in the CPR system during September’ (translated),” he said. “While this may not be a direct factor in this case, delays are common when a breach originates from a third-party. It highlights why organisation must perform substantial due diligence to ensure breach notifications from external parties match the internal standard.”

The case has been reported to Datatilsynet, the Danish Data Protection Agency, which received notification on Sunday and said it could not yet comment on the specifics. Police are also investigating, and Egelund has ordered a thorough security review of the CPR system.

What those affected should do

Egelund has urged people in Denmark to stay vigilant and follow official digital security guidance in the coming weeks.

“Anyone affected should remain alert to phishing emails, text messages and calls, particularly those claiming to come from banks or public authorities,” said Akhtar. “Knowing your name, address or identification number does not make a caller trustworthy.”

He went on: “Customers must verify requests through an official website or a known telephone number, check accounts for unusual activity and report suspected fraud promptly. Change any passwords known or suspected to be compromised, including wherever they have been reused, and enable multi-factor authentication (MFA), or passkeys where available. Changing a password cannot undo the exposure of personal information, but it can help protect an affected account.”

“For the future, individuals should use unique passwords stored in a password manager, keep devices updated and make secure authentication a habit.”

Lessons for organisations

For organisations holding sensitive data, the experts’ message centred on supplier access and monitoring. “To defend against this threat, governments and businesses must also strictly limit what external partners are allowed to view,” said Agha. “They must also monitor these systems continuously to detect unusual search patterns before millions of records are extracted.”

Akhtar said: “Organisations must take responsibility for protecting the information entrusted to them. Collect and retain only what they need, restrict access to what each user or supplier requires, and monitor for unusual activity. Regular supplier security reviews, staff training and rehearsed incident response plans should support these controls. This incident is a reminder that a trusted supplier’s access needs the same scrutiny as an organisation’s own systems.”

Davies-Webb added: “This breach also highlights the importance of assessing risk correctly and going beyond identifying systems that serve a critical function. Many cyber security frameworks recommend quantifying data in terms of value and volume, and identifying scope for abuse, which must include third parties. Centralised systems like this should be treated with the utmost importance. That can include mandating stronger authentication, shorter sessions, rate limiting data requests and creating a baseline of normal behaviour to support monitoring.”

Pamplin argued for protection at the data layer itself. “National identity registers demand protection applied directly to the data itself. Data-centric, quantum-safe controls ensure that even where legitimate access channels are abused, what is extracted remains unreadable and unusable outside its authorised context.”

Davies-Webb, however, struck a positive note on the authorities’ handling so far. “Overall, it is very positive to see the current transparency, especially the extended hours on the digital security hotline. These behaviours can indicate that response plans are in place and being followed.”

ShareTweet
Previous Post

Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

Next Post

Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

Recent News

Q&A With Oliver Simonnet at CultureAI: AI Security In 2026: Most Organisations Deploy AI And Hope For The Best

Q&A With Oliver Simonnet at CultureAI: AI Security In 2026: Most Organisations Deploy AI And Hope For The Best

October 5, 2026
Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

October 5, 2026
Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access

Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access

October 5, 2026
Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

October 5, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol