Opens in a new tab

Funen company at centre of Denmark’s largest CPR data breach

Friday 9th October 2026 on 13:01 in Denmark

CPR register, data breach, denmark

A small software company on Funen is at the centre of what DR reports is the largest leak in Denmark’s history of civil registration numbers and addresses.

The company, which advertises “highly secure data protection”, had legal access to Denmark’s CPR register, the national civil registration number database. That access was compromised. DR has not named the company while it seeks comment and has been unable to reach it since Thursday morning.

DR’s research found that one password used by the company had been exposed in a data leak. The password was “123456”. DR has not established whether that particular login was used in the attack. The information is consistent with details an anonymous alleged hacker gave to Politiken about how the breach was carried out.

DR does not know the alleged hacker’s identity, nationality or possible affiliations. Politiken has reported that the person communicated with its journalists in English and that the newspaper has seen documentation relating to nearly 8.8 million civil registration numbers taken from the system. Politiken has not said what it will do with the data or how it is handling it.

DR found a login page that may have been used to gain access to the company’s CPR account. The company’s name was removed from the image. A 2025 data leak also included what may be an employee’s email address and password, although the password was partly obscured. DR says it saw the full password in another leak and has redacted the URL and username.

Documents obtained by DR show that the company’s access was blocked the day before the CPR Administration reported the incident to the Danish Data Protection Agency on October 3. The theft took place between September 10 and 20. A CPR Administration employee raised the alarm after noticing an unusually high bill for the company.

The CPR Administration said it has introduced a fixed billing check to identify unusual use of CPR services and help prevent compromises at organisations with access. It said further measures were being considered.

The authorities are responsible for ensuring that companies with access to the CPR register meet an adequate security standard. The National Unit for Special Crime is investigating. It declined to comment to DR, and no one has been charged.

Source 
(via DR)