8.8 million
On October 5, 2026, Danish authorities announced a major data breach of the Denmark Central Person Register (CPR), the national population database. The incident exposed the personal data of approximately 8.8 million individuals, including current and former residents. The attackers did not exploit a technical vulnerability but instead abused the legitimate access credentials of a trusted third-party company. For about 10 days, the threat actors executed a high volume of automated queries to exfiltrate names, addresses, and the unique 10-digit CPR identification numbers. This breach is considered "deeply serious" by the Danish government due to the central role the CPR number plays in daily life, and a police investigation has been launched.
The data breach occurred in September 2026 when an unidentified threat actor gained control over and misused the account of a private Danish company. This company had legitimate, authorized access to query the CPR system. Instead of hacking the CPR directly, the attackers leveraged this trusted relationship to harvest data at scale. This method is often referred to as a supply chain or third-party attack, where the target's security is circumvented by compromising a less secure partner.
The attackers performed a large number of automated queries over approximately 10 days, a pattern of activity that was flagged as unusual by the register's administration on October 2, 2026. The compromised data includes:
The government has assured that individuals with protected name-and-address status were not affected by this breach.
The attack vector was the abuse of legitimate credentials, a form of T1078 - Valid Accounts. The attackers specifically exploited a T1199 - Trusted Relationship between the Danish government and the private company. The core of the data exfiltration was a 'smash and grab' operation using automated scripts to make a high volume of queries. This suggests the attackers focused on data collection rather than persistence or lateral movement within the CPR system itself.
The detection of the breach was based on anomaly detection, specifically the unusual surge in query volume from the compromised company's account. This highlights the importance of monitoring the behavior of even trusted, authorized users.
This is a highly significant data breach with severe potential consequences for the 8.8 million affected individuals. The CPR number is a national identification number in Denmark, used for nearly all interactions with public authorities and many private services like banking, healthcare, and insurance. The exposure of this number alongside names and addresses creates a critical risk of:
The breach undermines public trust in Denmark's highly digitized public sector and has prompted a full security review of the CPR system and its third-party access policies.
No specific Indicators of Compromise (IOCs) such as IP addresses or domains were provided in the source articles.
For organizations managing sensitive databases with third-party access, the following patterns could indicate similar activity:
Regularly audit and monitor access logs, especially for third-party accounts, to detect anomalous behavior.
Enforce the principle of least privilege for third-party access, providing access only to necessary data and implementing strict query limits.
Mapped D3FEND Techniques:
Use behavior analytics to detect unusual patterns of access, such as a sudden high volume of queries from a single account.
Approximate start of the 10-day period during which attackers made automated queries to harvest data.
The CPR administration detects unusual activity (a surge of automated queries) from the private company's account.
The Danish Data Protection Agency is formally notified of the breach.
Danish authorities publicly disclose the data breach.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.