The Denmark CPR Data Breach Took the One Number Nobody Can Reissue

The Denmark CPR Data Breach Took the One Number Nobody Can Reissue

A man who left Denmark in 2011 has not filed a Danish tax return in fifteen years. He has no Danish address and no reason to follow Danish news. But his name, his birth date, his last Danish address, his marital status and his CPR number all sat in the national register anyway. Now they sit in a copy somebody made. Because he moved away, any notice about it goes to an address he left behind. That is the shape of the Denmark CPR data breach: the people hardest to warn are inside it.

Confirmation: confirmed by the CPR administration and the Danish Data Protection Agency, and reported on October 5, 2026.

What happened in the Denmark CPR data breach

Nobody picked the lock. The attackers abused a private Danish company’s lawful access to query the register, so every request they made looked like business as usual.

The Central Person Register, known as CPR, is Denmark’s national civil registry. Thousands of organizations query it legitimately every day. According to the Danish Data Protection Agency, the attackers used brute-forcing to enumerate valid CPR numbers, then extracted the data attached to each entry. In short, they walked the register one number at a time.

The intrusion took place in September 2026. Staff discovered it on October 2, and the authorities disclosed it on October 5. Nobody has yet named the company whose access the attackers borrowed.

The count is disputed, so here are both figures. BleepingComputer reports 8.8 million people, roughly 80 percent of the 11 million records the register holds, while TechCrunch reports 8 million. Either way the file reaches past the living population of about 6 million, because the register also covers people who moved abroad and people who have died. Minister Christina Egelund called it an extremely serious incident.

What the Denmark CPR data breach exposed

Five fields went out: names, addresses, CPR numbers, dates of birth and marital status. No email addresses and no phone numbers appear in the announcement.

The CPR number is the item to worry about first. It is the key to Danish public services, banking and healthcare, and it is not something a person can rotate after a bad week. A password can be changed in a minute. A national identity number cannot, so the exposure here does not expire.

The rest of the file is what makes impersonation work. An address places you. A birth date confirms you. Marital status supplies the small domestic detail that makes a stranger on the phone sound like somebody with a file open in front of them. For example, a caller who already knows those four things does not need to ask you to verify anything, which is exactly why the call does not feel like a scam.

Why a borrowed login reached millions of records

The register’s own defenses were not the failure point. A trusted third party’s access was, and somebody could run that access at machine speed before anyone noticed.

This is the uncomfortable pattern in modern breaches. Your data is rarely exposed where you put it. It is exposed at the fourth company down the chain, the one you have no relationship with and were never asked about. The same shape showed up last week in the DTU breach, where compromised user profiles opened a university identity system holding 23 years of records.

Discovery took until October 2 for an intrusion that happened in September. Because the queries looked legitimate, there was no failed-login spike to catch.

What to do now

Most of this has nothing to do with us.

  • Assume you are in scope if you have ever had a CPR number, including if you left
  • Denmark years ago or never lived there full time.

  • Treat any contact that recites your details as suspicious, not as proof. Knowing your
  • CPR number, address and birth date is now cheap. So hang up, then call back on a number you looked up yourself.

  • Watch for mail and messages dressed as the authorities. The follow-up wave after a
  • registry breach impersonates the institutions people are told to trust, because that is what the news has primed everyone to expect.

  • Put a password manager on every account that still uses a password, with one unique
  • password each.

  • Turn on the strongest sign-in each account offers. Where a service supports passkeys
  • or hardware keys, take those over codes sent by text.

  • Tell the older relatives in your family what happened. They are the ones a caller
  • with a file will try first.

How OptMsg changes this exposure

OptMsg did not stop this and could not have. The data left a national register, not anybody’s inbox. What an inbox changes is the second wave, and this breach has an unusually clear one: the file held no email addresses, so the scams built on it must arrive at addresses harvested somewhere else.

Two mechanisms are worth naming at their real size. First, an OptMsg account has no password, so a password leaked from another site cannot be tried on the inbox. Because email is the reset-and-recovery route into most other accounts, a door a stolen credential cannot open tends to keep the accounts behind it shut too. Second, mail from a sender you have not approved goes to Trash instead of your Inbox, and it auto-deletes after 30 days. The message dressed up as a government agency lands there.

Here is what that argument does not cover, stated plainly. It does nothing about a compromised device, a live phishing page you type your details into, or an attacker holding your unlocked phone. It does nothing about a CPR number already sitting in somebody’s database, and it does nothing about a phone call. What it narrows is the blast radius on your side, and that is the whole claim.

If the volume of strangers holding your details is the part that bothers you, read how OptMsg thinks about who gets to reach you, or start an account and see what an inbox with a guest list feels like.

Create Your Account

Your Inbox. Your Rules.

Frequently asked questions

Was I affected by the Denmark CPR data breach? If you hold or have ever held a Danish CPR number, treat yourself as in scope. The exposed set covers roughly 80 percent of the register, including people who moved abroad and people who have died, so the safe assumption is the broad one.

What exactly was taken? Names, addresses, CPR numbers, dates of birth and marital status. Email addresses and phone numbers are not in the announcement.

Can I get a new CPR number? Not as a routine remedy. That is what separates this from a password leak: the identifier stays the same, so the sensible response is to assume callers and senders already know it and to stop treating it as proof of who they are.

Were passwords stolen in the Denmark CPR data breach? No. The attackers read the register through a third party’s legitimate access instead of cracking anybody’s credentials, which is also why it took until October 2 to notice.

Does a new email address help if my CPR number is already out? It helps with the second wave rather than the first. The number is out and it stays out. But an address that only accepts mail from senders you approved gives the follow-up scam nowhere to land.

Sources

  • BleepingComputer, Denmark population registry data breach affects 8.8 million people, 2026-10-05 — https://www.bleepingcomputer.com/news/security/denmark-population-registry-data-breach-affects-88-million-people/
  • TechCrunch, Hackers steal 8 million citizens’ records from Danish government database, 2026-10-05 — https://techcrunch.com/2026/10/05/hackers-steal-8-million-citizens-records-from-danish-government-database/
Scroll to Top