INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Denmark's Central Person Register Exposed in Cyberattack to 8.8 Million
| 2026-10-06 12:00 CRITICAL LOW DATA BREACH INDUSTRY & POLICY
Executive Summary
AI-generated
A significant data breach occurred in Denmark, affecting the Central Person Register (CPR), a national population database containing approximately 8.8 million individuals' names, addresses, and CPR numbers. The breach was detected after a surge in automated queries triggered an internal investigation on October 5, 2026, following a prolonged period of exploitation by attackers that lasted about 10 days in September 2026. Authorities have suspended the implicated company's access, notified the Danish Data Protection Agency (Datatilsynet), and launched a police investigation to address potential risks associated with centralized national databases and third-party access, which may lead to identity theft and fraud due to the exposure of lifelong identifiers.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
id•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORDICS
NORDICS
NORTH_AMERICA
NORTH_AMERICA
healthhealth
retailretail
hospitalityhospitality
technologytechnology
Incident Timeline
September 4
Hackers obtained user data held in the identity verification company's cloud platform.
September 2026
Threat actors launched a cyberattack that exposed data of 8.8 million individuals in Denmark's Central Person Register (CPR) over approximately 10 days in September 2026.
Click on any entity below to view its context and source!
organisation
Danish Data Protection Agency
Authorities have suspended the implicated company’s access, notified the
Danish Data Protection Agency (Datatilsynet)
, and launched a police investigation.
organisation
Datatilsynet
Authorities have suspended the implicated company’s access, notified the
Danish Data Protection Agency (Datatilsynet)
, and launched a police investigation.
October 5, 2026
Threat actors exploited a legitimate company account to access the names, addresses, and CPR numbers of approximately 8.8 million individuals in Denmark's Central Person Register.
Click on any entity below to view its context and source!
target_region
Denmark
Rescana’s new report on a breach affecting the Denmark Central Person Register (CPR) summarizes the situation:
On October 5, 2026, Danish authorities publicly disclosed a significant data breach affecting the
Central Person Register (CPR)
, Denmark’s national population database.
tactic
Data Breach
Rescana’s new report on a breach affecting the Denmark Central Person Register (CPR) summarizes the situation:
On October 5, 2026, Danish authorities publicly disclosed a significant data breach affecting the
Central Person Register (CPR)
, Denmark’s national population database.
organisation
Central Person Register
Rescana’s new report on a breach affecting the Denmark Central Person Register (CPR) summarizes the situation:
On October 5, 2026, Danish authorities publicly disclosed a significant data breach affecting the
Central Person Register (CPR)
, Denmark’s national population database.
2026/10/06
A cyberattack on IDScan.net's databases resulted in the theft of personal data and scans of 153 million people's drivers' licenses.
Click on any entity below to view its context and source!
organisation
Denmark Central Person Register
Denmark Central Person Register (CPR) Breach: Cyberattack Exposes Data of 8.8 Million.
organisation
Cyberattack Exposes Data
Denmark Central Person Register (CPR) Breach: Cyberattack Exposes Data of 8.8 Million.
organisation
Canada Philippe Dufresne
Privacy Commissioner of Canada Philippe Dufresne has launched a probe of
IDScan.net
in the wake of reports that a bad actor penetrated company databases to steal personal data and scans of 153 million people's drivers’ licenses.
data_breach
1 September
IDScan learned of the breach on or around September 1, hours after journalist Brian Krebs
revealed
the scans were on sale on the dark web.
Tactical Metrics
Metrics
data_breach
1
September
Click for context!
IDScan learned of the breach on or around September 1, hours after journalist Brian Krebs
revealed
the scans were on sale on the dark web.
Intelligence Sources
TheRecord
2026-09-22
Data Breaches
2026-10-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:35
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
organisation
Identified Entity
Denmark Central Person Register
entity
4x
timeline
Temporal Reference
October 5, 2026
date
3x
industry
Targeted Sector
Technology
sector
2x
target region
Target Country
Denmark
country
Contextual Telemetry
Context Block
4 METRICS
tactic
Cyber Operation Type
Data Breach
tactic
general metric
Individuals
8,800,000
individuals
general metric
People
153,000,000
people
data breach
September
1
september
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.