CPR data leak raises questions over fraud and e-Boks
Tuesday 6th October 2026 on 18:01 in
Denmark
Hackers have obtained nearly nine million Danish personal identification numbers, names and addresses after misusing a company’s access to the system, DR reports. Readers asked DR legal correspondent Louise Dalsgaard and security expert Sofie Freja Christensen how to protect themselves.
Can someone get a credit card using a CPR number?
Not with a CPR number alone, Dalsgaard said. She said criminals also cannot take out a loan or buy things using only the number. They may try if they have other information, but taking out a loan requires identity confirmation with MitID.
Fraudsters may use details such as CPR numbers, addresses and spouses’ names to gain the trust of people they are targeting, she said.
Why not replace the CPR system?
Christensen said it is possible to abolish the 10-digit CPR number, but it is built into many systems. The problem, she said, is not the number itself, but that some organisations still use it as proof of identity, mainly over the phone.
MitID is already a secure identity system, she said. The CPR number should never be enough on its own, and access to registered data should be better controlled.
Is post in e-Boks still safe?
The leak does not by itself give anyone access to send post through e-Boks, the digital mailbox service said. The security of messages sent and received through the service has therefore not changed, according to e-Boks communications director Susanne Søndahl Wolff.
She said the situation would be different if unauthorised people gained access to a company’s or public authority’s systems for sending messages. Organisations must protect those systems and access, she said, adding that people can continue to have the same trust in e-Boks messages as before the leak.
Could the leak expose someone to an abusive former partner?
A reader told DR she feared that exposure of her address could put her at risk from her former husband and force her to move. Dalsgaard said people with protected names and addresses in the CPR register should be more reassured, as the information so far was that unauthorised people had not accessed their data.
Dalsgaard also said the digitalisation minister had demanded a full review of the system’s security and who was responsible. She expected changes to follow.