Opens in a new tab

Motor Registry breach exposed birth dates of 71,080 Danes

Friday 18th September 2026 on 16:31 in Denmark

data breach, denmark, Motor Registry

A security flaw in Denmark’s Motor Registry exposed the names, addresses and birth dates of 71,080 people, DR News reports. The flaw remained open nearly five years after it was introduced and is not due to be closed until 22 September.

The affected people had specifically requested name and address protection. In April, they were told that 59 companies had been able to look up their names and addresses in the registry since 2021.

Motor Agency told DR News that its own investigation found that 71,080 people were affected by the security breach. The agency had previously said that companies could access only names and addresses. Birth dates were later found to have been exposed as well, and they remain accessible until the flaw is closed.

The vulnerability was identified on 4 July 2025. Closing it on 22 September will come one year and two months after it was discovered.

“It is unbelievable that more information is now coming to light. Why have they not been open about this from the start?” said Anders Friis, one of the affected people. He described himself as shaken and said he was now questioning whether he had been told everything about the breach.

Friis previously worked as a municipal SSP employee, working with police and young people at risk of entering a life of crime. He said he did not want such people to have access to his personal information and declined to be pictured for the same reason.

“A birth date is, to me, like handing a key to people with bad intentions,” Friis said. He noted that birth dates are often used as security questions when resetting passwords and could therefore help people gain access to accounts.

Documents obtained by Friis show that several recycling centres, parking companies and a debt collection company had accessed his information. He said he had never knowingly been involved in a debt collection case and questioned why the company had looked him up. DR News was unable to reach the company.

Motor Agency said the breach involved 59 companies with approved terminal access to the Motor Registry. They included 26 recycling centres, 22 parking companies, four debt collection companies, four financing companies, a rescue service, a state-owned company and a guarantee fund.

Friis said he was also concerned that the information could be exposed through the companies’ own systems. In what is known as a supply chain risk, he said that giving 59 companies access created 59 opportunities for people with bad intentions to hack into those systems and obtain the information.

Several experts have said that the continued exposure of birth dates may directly breach GDPR rules. Motor Agency said it took the breach involving people with protected names and addresses very seriously, apologised to all affected people and would launch a further investigation.

Source 
(via DR)