Full Report
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to
Analysis Summary
# Incident Report: Unauthorized Access to Denmark's National Population Register (CPR)
## Executive Summary
Unauthorized parties exploited the legitimate access credentials of a private Danish company to perform millions of automated lookups in the Central Person Register (CPR). The incident resulted in the compromise of personal identification numbers, names, and addresses for approximately 8.8 million individuals (living and deceased). The Danish Digitalization Ministry has suspended the company's access and initiated a criminal investigation while advising citizens on identity theft mitigation.
## Incident Details
- **Discovery Date:** October 2, 2026
- **Incident Date:** September 2026 (Approx. 10-day duration)
- **Affected Organization:** Danish Central Person Register (CPR) / Ministry of Digitalization
- **Sector:** Government / Public Sector
- **Geography:** Denmark
## Timeline of Events
### Initial Access
- **Date/Time:** September 2026
- **Vector:** Exploitation of a third-party private company's lawful access rights.
- **Details:** Attackers gained unauthorized control over a small Danish company's account, which had legal permission to query the national register.
### Lateral Movement
- **Details:** Not explicitly disclosed; the attack focused on leveraging established API/lookup permissions rather than internal lateral movement within the government network.
### Data Exfiltration/Impact
- **Details:** Attackers conducted a "very large number of automated lookups." They successfully retrieved data for 8.8 million people, roughly 80% of the total records (11 million) stored since 1968.
### Detection & Response
- **Discovery:** October 2, 2026, when an administrator noticed "unusual activity" (high volume of lookups).
- **Response:** The ministry suspended the third-party company’s access immediately. On October 5, 2026, the incident was publicly disclosed and reported to Datatilsynet (Data Protection Authority).
## Attack Methodology
- **Initial Access:** Valid Credential Use / Third-Party Compromise.
- **Persistence:** Maintained access for 10 days via the company's legitimate portal.
- **Discovery:** Automated Reconnaissance/Enumeration of valid CPR numbers.
- **Collection:** Automated querying of the CPR database.
- **Exfiltration:** Data retrieved via legitimate lookup responses.
- **Impact:** Mass data breach of sensitive national identifiers.
## Impact Assessment
- **Financial:** Potential for high fraud-related costs; specific government mitigation costs unknown.
- **Data Breach:** Names, addresses, and CPR (National ID) numbers of 8.8 million people (living and dead).
- **Operational:** Suspension of services for the involved private company; increased load on government cyber hotlines.
- **Reputational:** Significant public concern regarding the security of the national identification system and third-party vetting.
## Indicators of Compromise
- **Behavioral indicators:** Unusual spike in CPR lookup volume; automated/scripted query patterns originating from a single company account; queries occurring outside of normal business patterns.
## Response Actions
- **Containment:** Revoked the third-party company's access credentials to the CPR system.
- **Eradication:** Investigation into the compromised company's systems to determine the breach source.
- **Recovery:** Public advisory issued; extended hours for the Cyberhotline (+45 33 37 00 37); implementation of "Credit Warning" (Kreditadvarsel) markers for citizens.
## Lessons Learned
- **Key takeaways:** Third-party access represents a massive surface area for national security risks. Automated "scraping" or high-volume lookups should have triggered automated alerts earlier than day 10.
- **Areas for improvement:** Rate limiting and anomaly detection for "lawful" API lookups were insufficient to prevent mass data harvesting.
## Recommendations
- **Prevention:** Implement strict rate-limiting on all third-party lookup accounts.
- **Monitoring:** Deploy AI-driven behavior monitoring to flag non-human query patterns in real-time.
- **Authentication:** Require Multi-Factor Authentication (MFA) for all private entities accessing national registers.
- **Vetting:** Regularly audit the cybersecurity posture of private companies granted lawful access to sensitive government databases.