<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/denmark-s-cpr-breach-14-million-lookups-in-ten-days-found-through-a-bill-jbuipgfqv" -->

---
title: Denmark’s CPR breach: 14 million lookups in ten days,...
description: Denmark's digitalisation ministry disclosed that unknown actors abused a private company's legitimate access to the Central Person Register (CPR) to pull...
canonical: https://daily.dev/posts/denmark-s-cpr-breach-14-million-lookups-in-ten-days-found-through-a-bill-jbuipgfqv
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Denmark’s CPR breach: 14 million lookups in ten days, found through a bill | daily.dev
og:description: Denmark's digitalisation ministry disclosed that unknown actors abused a private company's legitimate access to the Central Person Register (CPR) to pull...
og:url: https://daily.dev/posts/denmark-s-cpr-breach-14-million-lookups-in-ten-days-found-through-a-bill-jbuipgfqv
og:image: https://api.daily.dev/og/posts/jBUipGfQv.png
og:image:alt: Denmark’s CPR breach: 14 million lookups in ten days, found through a bill
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Denmark’s CPR breach: 14 million lookups in ten days, found through a bill

**[The Next Web](https://daily.dev/sources/tnw)** · 3 min read · 0 upvotes · 0 comments

## Summary

Denmark's digitalisation ministry disclosed that unknown actors abused a private company's legitimate access to the Central Person Register (CPR) to pull names, addresses and ID numbers on about 8.8 million people, out of roughly 11 million records in the register. The lookups ran for ten days in September and only surfaced when the CPR administration billed the firm for an unusually large number of queries. Police have identified no suspects. Officials, including civil security agency head Laila Reenberg, are now telling institutions to stop treating a bare CPR number as proof of identity, and the minister has ordered a security review with no set deadline.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/denmark-cpr-breach-8-8-million-records>

## Questions this post answers

### How was the Danish CPR register breach discovered?

It came to light through routine billing: companies pay per lookup against Denmark's Central Person Register, and when the CPR administration billed the firm involved, the invoice reflected an unusually large volume of activity. The ministry spotted the irregular activity on the evening of October 2, then established the scale of the breach over the following weekend.

_Incident writeups like this help developers building audit and billing alerts spot abuse earlier, something to track on daily.dev._

### How many records were exposed in the Denmark CPR data breach?

About 8.8 million records were returned out of more than 14 million lookup attempts made over a ten-day period in September. Denmark's CPR register holds roughly 11 million records total, including deceased people and those who moved abroad, while the country itself has about 6 million residents. People who had opted into name and address protection were not affected.

_Developers handling national ID data can follow breach scale details like these on daily.dev to gauge real exposure risk._

### Why are officials telling companies to stop accepting a CPR number alone as proof of identity?

Because a CPR number by itself is no longer considered secure after the breach exposed millions of records, according to Laila Reenberg, head of Denmark's civil security agency. She said the number cannot be used to authorise transactions, make purchases, or access sensitive personal information, and specifically called out pharmacies that currently accept the number alone to find other verification methods.

_Teams designing identity verification flows can track this shift away from single-factor ID checks on daily.dev._

## Similar posts on daily.dev

- [Danish university DTU breach exposes data of up to 200,000 people](https://daily.dev/posts/danish-university-dtu-breach-exposes-data-of-up-to-200-000-people-l2s8cnaej) · BleepingComputer · 2 upvotes · 0 comments
- [15.8M medical records stolen from French health ministry](https://daily.dev/posts/15-8m-medical-records-stolen-from-french-health-ministry-wf933jtn2) · The Register · 0 upvotes · 0 comments
- [Another massive data breach exposed millions of driver’s license numbers](https://daily.dev/posts/another-massive-data-breach-exposed-millions-of-driver-s-license-numbers-z6spff7ie) · TechCrunch · 0 upvotes · 0 comments
- [I Changed One Number… and Got Access to Citizens’ ID and Address Proofs](https://daily.dev/posts/i-changed-one-number-and-got-access-to-citizens-id-and-address-proofs-qyneutnqa) · InfoSec Write-ups · 0 upvotes · 0 comments

---

Tags: [#privacy](https://daily.dev/tags/privacy), [#phishing](https://daily.dev/tags/phishing), [#data-breach](https://daily.dev/tags/data-breach), [#identity-verification](https://daily.dev/tags/identity-verification)

[View this post on daily.dev](https://daily.dev/posts/denmark-s-cpr-breach-14-million-lookups-in-ten-days-found-through-a-bill-jbuipgfqv)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Denmark’s CPR breach: 14 million lookups in ten days, found through a bill","url":"https://daily.dev/posts/denmark-s-cpr-breach-14-million-lookups-in-ten-days-found-through-a-bill-jbuipgfqv","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/denmark-s-cpr-breach-14-million-lookups-in-ten-days-found-through-a-bill-jbuipgfqv"},"datePublished":"2026-10-06T14:35:31.049Z","dateModified":"2026-10-07T16:07:08.104Z","description":"Denmark's digitalisation ministry disclosed that unknown actors abused a private company's legitimate access to the Central Person Register (CPR) to pull...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1e76452996a16236bfcd9864c2a0acac?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1e76452996a16236bfcd9864c2a0acac?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/denmark-s-cpr-breach-14-million-lookups-in-ten-days-found-through-a-bill-jbuipgfqv","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"privacy,phishing,data-breach,identity-verification","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"Denmark’s CPR breach: 14 million lookups in ten days, found through a bill"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/denmark-s-cpr-breach-14-million-lookups-in-ten-days-found-through-a-bill-jbuipgfqv#faq","mainEntity":[{"@type":"Question","name":"How was the Danish CPR register breach discovered?","acceptedAnswer":{"@type":"Answer","text":"It came to light through routine billing: companies pay per lookup against Denmark's Central Person Register, and when the CPR administration billed the firm involved, the invoice reflected an unusually large volume of activity. The ministry spotted the irregular activity on the evening of October 2, then established the scale of the breach over the following weekend. Incident writeups like this help developers building audit and billing alerts spot abuse earlier, something to track on daily.dev."}},{"@type":"Question","name":"How many records were exposed in the Denmark CPR data breach?","acceptedAnswer":{"@type":"Answer","text":"About 8.8 million records were returned out of more than 14 million lookup attempts made over a ten-day period in September. Denmark's CPR register holds roughly 11 million records total, including deceased people and those who moved abroad, while the country itself has about 6 million residents. People who had opted into name and address protection were not affected. Developers handling national ID data can follow breach scale details like these on daily.dev to gauge real exposure risk."}},{"@type":"Question","name":"Why are officials telling companies to stop accepting a CPR number alone as proof of identity?","acceptedAnswer":{"@type":"Answer","text":"Because a CPR number by itself is no longer considered secure after the breach exposed millions of records, according to Laila Reenberg, head of Denmark's civil security agency. She said the number cannot be used to authorise transactions, make purchases, or access sensitive personal information, and specifically called out pharmacies that currently accept the number alone to find other verification methods. Teams designing identity verification flows can track this shift away from single-factor ID checks on daily.dev."}}]}
```

