Unknown parties got into Denmark's Civil Registration System (CPR) without authorisation. They accessed the names, addresses and CPR numbers of about 8.8 million registered people, the ministry announced on 5 October 2026.
They got in by misusing a Danish private company's legitimate search access to the system. Under the CPR Act, companies with a legitimate interest may look up information on individuals. The register holds about 11 million people, including people who have died or emigrated. The unauthorised access did not include names and addresses covered by registration protection.
The CPR administration spotted irregular activity on the system on the evening of 2 October. The unauthorised access was confirmed over the weekend. The company's access has since been cut off.
The incident has been reported to the Danish Data Protection Agency. Police are investigating together with other relevant authorities. The investigation is at an early stage, and the responsible party has not yet been identified. A thorough security review of the CPR system has begun.
— This is a deeply serious incident, said Christina Egelund, Minister for Research, Education and Digitalisation.
She has briefed the Danish parliament's Business and Digitalisation Committee.

