What happened in the CPR data breach?
On 5 October 2026, Denmark's CPR administration disclosed unauthorized access to names, addresses, CPR numbers and other information concerning about 8.8 million registered people. Someone had misused a Danish company's legitimate access to the Central Person Register. The administration blocked that company's access and reported the incident to Datatilsynet, Denmark's data protection authority. Police are investigating, according to the CPR administration's notice.
For readers, the immediate concern is what someone could do with those details. A caller who knows your name and CPR number can sound credible. Those details should never be enough to win your trust.
What the numbers and protections mean
The figure includes people who have died or moved abroad, as well as living residents. It should not be read as 8.8 million people currently living in Denmark. Authorities became aware of irregular activity on 2 October, relating to access during September, according to the ministry's announcement.
That announcement says protected names and addresses were excluded. It does not say that every data field belonging to a person with name and address protection was unaffected. It also does not establish how the company's access was first obtained or confirm that the records were publicly published.
These distinctions matter when deciding what to do next. Confirmed unauthorized access is enough reason to review identity checks, without assuming that every possible consequence has already happened.
How personal details can make a scam convincing
Imagine an unexpected call from someone claiming to help you after the breach. They read out your address, then ask you to approve a login or hand over a code to “secure” your account. This is a hypothetical example, but it shows the problem: accurate information can make a false request feel legitimate.
The caller's knowledge tells you something about the information they possess. It tells you very little about who they are or whether you should follow their instructions. The same applies when a message uses an official-looking logo or refers to a real news story.
This is the human side of phishing: someone gives you a believable reason to take an action that benefits them. After a breach, employees need to recognize that even a message containing correct personal details still needs checking.
What you can do now
The official fraud guidance shared by Arbejdstilsynet advises caution with unexpected messages and calls that use your personal information.
- Verify contact independently. Open the organization's official website yourself or call its main number. Avoid links supplied in an unexpected message.
- Keep credentials private. Do not give an unexpected caller your MitID details, passwords, one-time codes or card details.
- Consider a credit warning. Read the guidance before deciding whether to add one to your CPR record.
A credit warning asks lenders to take extra care before granting credit in your name. It is not a universal block: receiving the warning is optional for companies, and it can also make your own credit applications harder. Borger.dk's English guidance explains the benefits and limitations.
If you need to understand the difference between exposed information and someone actually misusing your identity, our guide to identity theft and how to deal with it explains the next steps.
What organizations should change in identity checks
On 6 October, Styrelsen for Samfundssikkerhed urged organizations to supplement their identity checks. Its recommendations include using authenticated self-service, calling back on a number already held on file, and applying manual review or a waiting period to consequential changes.
Start with the moments when a mistake would matter most: releasing personal information, changing payment details or helping someone regain account access. Ask staff to walk through what they would do if a caller provided the correct name, address and CPR number.
If those details alone are enough to complete the request, the process needs stronger verification. Give employees a clear alternative and a way to escalate uncertainty. A general instruction to “be careful” leaves each person to invent a response under pressure.
The most useful next step is concrete: choose one customer-service or account-recovery process and check what evidence it accepts as proof of identity. Personal information can help locate a record. Access to that record needs a separate check.




