Criminals can misuse stolen Danish CPR numbers in five ways
Monday 5th October 2026 on 15:45 in
Denmark
Criminals could use stolen Danish personal identification numbers to target people with scams, commit identity theft and obtain further information about them, DR reports. The warning follows the unauthorised access to 8.8 million CPR numbers in what the article describes as the largest breach of Denmark’s CPR register.
A CPR number is a ten-digit personal identification number. On its own, it is not likely to cause significant harm, said Jens Myrup Pedersen, a cybersecurity professor at Aalborg University. But it could become dangerous when combined with other information or used in a follow-up attack.
Five possible uses
First, scammers could use the numbers to make phishing messages more convincing. They might pose as a bank, energy company, doctor or hospital, and knowing a person’s CPR number could make the contact appear genuine.
Second, the information could be used for identity theft. Pedersen said it would be enough to fill in a health insurance card, which could be shown as identification, for example when someone receives a fine on a train. Combined with a photograph found on social media, the data could also be used to create a convincing driving licence.
Third, CPR numbers can help scammers identify potential targets. Combined with addresses, they can show where people live and how old they are. Pedersen said this could help criminals locate older people, whom he described as common targets for fraud involving direct contact, whether online, by phone or in person.
Fourth, the data could be sold to others who specialise in phishing and identity theft, allowing it to spread further.
Fifth, a CPR number could be used to seek more sensitive information about a person from places such as a pharmacy or a doctor. Pedersen said people may need to get used to the idea that a number can no longer be treated as secret.
How to reduce the risk
It is not yet known exactly who has been affected by the stolen information. The advice in the article is to avoid sharing CPR numbers or MitID login details by email, text message or phone; check that a sender’s email address matches the organisation they claim to represent; and contact the organisation directly if uncertain.
People should not be pressured by urgent deadlines or click unknown links asking them to update or confirm information. Anyone seeking to make it harder for others to take out loans or credit in their name can set up a credit alert on borger.dk. The advice is based on information from Sikkerdigital.dk and the Danish Data Protection Agency.