Denmark's Central Person Register administration disclosed on 5 October 2026 that unauthorized parties reached personal data on about 8.8 million registered people. The entry point was not a public website. It was a private Danish company's legitimate permission to search the register.
What happened
The Ministry of Research, Education and Digitalisation said the access covered names, addresses, CPR numbers, and other data the company was allowed to query. People registered with name and address protection were not included.
The register holds about 11 million records, including living residents, people who have died, and people who have emigrated. The administration noticed irregular behaviour on the evening of Friday 2 October. The activity itself ran through September. Digitalisation minister Christina Egelund later told Ritzau the misuse lasted about ten days and that the company's access controls were not good enough.
The company's access has been cut off. The incident was reported to Datatilsynet, and police are investigating. The ministry has ordered a security review of the CPR system.
Who is affected
Anyone whose record sits in the Danish population register and was not under name-and-address protection is in scope. That is larger than Denmark's resident population because the register keeps historical records.
For an MSP, the lesson is vendor identity, not a Danish-only firewall rule. A partner account with broad lookup rights, weak monitoring, and a ten-day dwell time is enough to empty a high-value directory.
What to do now
- Review every partner login that can query identity, payroll, or citizen-style directories, and cut unused ones today.
- Alert on bulk lookups, off-hours queries, and exports from those accounts.
- Treat any call or email that already knows a client's ID number, address, and name as a possible social-engineering lead.
- Confirm third-party access reviews are on a calendar, not a once-a-year spreadsheet.
Source: Danish Ministry of Research, Education and Digitalisation, 5 October 2026. Official statement.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- Zammad CVE-2026-102489: KEV due date is today
- CVE-2026-61500: Rejetto HFS admin session forgery
- ShinyHunters: suspected member detained in Jordan
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.