
Denmark's ID Database Leaked 8.8 Million People. The Country Only Has 6 Million.
Mahmud Hasan
October 7, 2026
The breach that hit more people than live in the country
On Monday, Denmark's digitalization minister stood in front of the press with a number nobody had planned for: 8.8 million. That's how many registered people's names, home addresses, and national ID numbers had been pulled out of the country's Central Population Register — the CPR — during September. Denmark has about 6 million residents. The breach hit 8.8 million people because the register doesn't forget: it keeps records for everyone who ever lived there, including people who died or moved away.
The minister, Christina Egelund, called it "an extremely serious incident." She briefed parliament's Business and Digitalization Committee the same day. The police are investigating. The company whose access was abused hasn't been named. And by Tuesday, one question was already hanging over the whole thing: does the entire country need new ID numbers?
How it happened: the front door, used 8.8 million times
Here's the part that should make every developer sit up. Nobody broke into the CPR's servers. No zero-day, no firewall failure, no malware. The attackers used a legitimate access channel — a small private Danish company's authorized lookup access to the register — and then hammered it with what Denmark's Data Protection Agency called a very large number of automated searches.
Under Danish law, private companies with a legitimate interest can look up CPR data on people they've already identified. The register's own guidance says a CPR number alone is enough to identify a person for that purpose, and that companies may only request data on people they already deal with — customers, employees, that sort of thing. Somewhere in September, that narrow channel became a firehose. The CPR administration spotted irregular activity on the evening of Friday, October 2. Over the weekend they mapped the damage: roughly 8.8 million records touched, about 80 percent of the register's 11 million entries. The company's access was cut, the Data Protection Agency was notified on October 4, and the public announcement followed on October 5.
Egelund herself admitted to Danish press that the safeguards around this kind of access had not been solid enough — and that alarms should have gone off sooner, given how long the abuse ran. A month of automated enumeration queries through a trusted partner's credentials, and nobody's rate-limit or anomaly alert fired until October.
The number was built to be guessed
The brute-forcing worked because Danish CPR numbers are predictable by design. Ten digits: the first six are the holder's date of birth (DDMMYY), followed by a four-digit serial. By one outlet's arithmetic, that's at most 10,000 possible numbers per date of birth — a search space you can walk through, date by date, person by person, and ask the register whether each one is real.
That predictability is a 1968 design decision. The CPR is one of the oldest civil registration systems in the world, and it was built for a world where a paper register's index key could double as an identity. It worked — for a while. The CPR number now unlocks everything: taxes, doctors, bank accounts, nearly every interaction with public and private services in Denmark.
Danish security specialist Jan Kaastrup told TV 2 this week that treating CPR numbers as secrets is a "broken" approach. His point was blunt: a number alone should never be accepted as proof of identity, because we now live in a fully digitized society and the number isn't secret anymore. The register's own official guidance already says as much — a CPR number "helps identify a person but must not be used as the only proof of identity." But when your whole country runs on one number, that guidance and reality drift apart.
Could everyone get a new number?
That's the question Egelund said was "too soon" to answer in a TV interview this week. Re-issuing CPR numbers for millions of people would mean untangling 58 years of records — banks, hospitals, tax systems, employers — all keyed on one number. The act governing the register already allows a new number in special cases where misuse is proven, but doing it at national scale is a different order of operation entirely.
There's a smaller, telling detail in the official statements: people who had registered for name and address protection — Denmark's opt-out for people who want their address hidden — were not exposed. The system had a protection mechanism, and it worked for those who used it. The other 8.8 million people get to be extra careful about suspicious calls and emails for a while, which is what authorities are now advising.
What developers should take from this
This wasn't a vulnerability in the code sense. Nobody found a buffer overflow or misconfigured S3 bucket. It was a design failure stacked three deep, and each layer is something you might recognize in your own systems.
- Predictable identifiers aren't secrets. If your IDs are sequential, date-derived, or otherwise guessable, treat them as public — because someone will enumerate them. Rate limits and anomaly detection are the minimum for any lookup endpoint.
- Trusted-partner access is an attack surface. The broadest access in your system often belongs to a third party — an integration, a vendor API key, a partner dashboard. The CPR register trusted a small company's credentials the way production trusts a service account. Monitor partner traffic like you monitor the front door.
- Alarms that nobody configured don't exist. A month of automated queries went unnoticed. If your system doesn't have anomaly alerts on lookup volumes per credential, you don't have anomaly alerts.
The hardest question here isn't technical. Denmark built the most digitized public sector in the world on a 1968 identifier, and it worked brilliantly — until the moment the number stopped being a secret. The minister now has to decide whether to re-issue ID numbers for a nation. That's the cost of a design assumption that outlived its safety margin by about three decades.
References
- Denmark's ID register spills more people's details than the country has residents — The Register
- Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account — The Hacker News
- 8.8 Million Impacted by Data Breach at Denmark's Central Person Register — SecurityWeek
- Denmark population registry data breach affects 8.8 million people — BleepingComputer
- Denmark's population register massive breach exposes data on 8.8 million people — Digital Watch Observatory
- Denmark's national population registry breach exposes data of 8.8 million people — TEISS
- Denmark's Central Registry Breach Exposes 8.8 Million Identities Through Trusted Company Access — WebProNews
- Denmark personal identification number entity definition — Microsoft Learn (CPR number format)
Comments
More in Cybersecurity

Apple's New CEO Just Made Himself Its Design Chief. He's an Engineer. That's the Point.
John Ternus visits Apple's design studio several times a week — Tim Cook came about once a month. Seven years after Jony Ive left, the CEO has made himself the company's design chief, and the bet is that one decision-maker beats a committee.
Read more
California Banned Robo Bosses. Your Performance Dashboard Survived.
On September 30, California became the first state to ban AI-only firings. The law has real teeth — but it doesn't touch the surveillance software scoring you every day. Here's the fine print.
Read more
1 in 8 Cancers Starts as an Infection. A Significant Share Is Preventable — We Are Just Not Acting.
A new IARC study published in The Lancet Oncology says 2.3 million cancers diagnosed in 2024 — one in eight — were caused by infections. Unlike the genetics story, most of these are preventable with vaccines, antibiotics, and screening we already have.
Read more