Opens in a new tab

Professor calls CPR data breach Denmark’s largest ever

Monday 5th October 2026 on 09:30 in Denmark

cybersecurity, data breach, denmark

Unauthorized access to names, addresses and CPR numbers belonging to about 8.8 million people is “the largest breach ever” involving Denmark’s CPR register, cybersecurity professor Jens Myrup Pedersen told DR’s P1 Morgen.

Pedersen, of Aalborg University, said the combination of CPR numbers and addresses made the breach especially extensive. In 2015, CPR numbers were accidentally sent on CD-ROMs to a Chinese company, but that data did not include addresses, he said.

It is not yet clear how the unauthorized access happened or who was responsible. The access was made through a company authorized to look up information in the CPR system.

Pedersen said access should be limited to the information companies need, with systems to flag or block unusually high numbers of searches. He also called for a review of the safeguards against unauthorized access and the requirements placed on companies that use the register. The Research, Education and Digitalisation Ministry became aware of the breach over the weekend.

The stolen information could help criminals make phishing attempts more convincing by using people’s CPR numbers or addresses, Pedersen said. It could also be used for identity theft or sold to others.

Source 
(via DR)