CSIS Tech Blog

CPR breach: misuse of trusted access | CSIS Security Group

Written by CSIS | Oct 9, 2026, 9:41:50 AM

The Central Person Register (CPR) incident disclosed on 5 October 2026 is one of the largest exposures of personal data in Danish history. Over roughly 10 days in September, unauthorised parties used a private company's legitimate access to retrieve names, addresses and CPR numbers for around 8.8 million registered individuals.

The scale has dominated the coverage, but the attack path is also instructive. No vulnerability in the CPR system was exploited. The login was valid, the queries fell within the data private companies are permitted to see, and security monitoring did not flag the activity. Misuse of trusted third-party access remains one of the hardest attack patterns to detect, and one to which most organisations are exposed.

Jan Kaastrup, Chief Cybersecurity Advisor at CSIS Security Group, has commented on the incident on DR and TV 2, and other Danish media. In the video below, he sets out three lessons for security teams.

 

 

Timeline of events

September: Over about 10 days, unauthorised parties ran queries in the CPR system through a smaller Danish company's legitimate access.

Friday 2 October: The CPR administration identified irregular activity in the system during September.

Weekend of 3–4 October: The CPR administration confirmed unauthorised access to names, addresses and CPR numbers for about 8.8 million registered people. The figure includes deceased and emigrated individuals. The register holds about 11 million records in total.

Monday 5 October: The ministry disclosed the incident. The company's access was revoked, the case was reported to the Danish Data Protection Agency, and police began investigating. The minister ordered a full security review of the CPR system.

Tuesday 6 October: At a press conference, the authorities said the activity was identified because of an unusually large invoice for the company's queries. There had been well over 14 million attempted queries. The Danish Agency for Civil Protection said CPR numbers can no longer be relied on to identify a person. Police could not yet say who was behind the incident.

Thursday 8 October: An anonymous hacker told the newspaper Politiken that they were behind the incident. The hacker says they logged in with a former employee’s leaked password, 123456. The claim has not been officially confirmed.

 

How the access was misused

Under Section 38 of the CPR Act, private companies with a legitimate interest can retrieve specified CPR data on individuals they have already identified. In this case, that access was used to query the register at a volume far beyond any plausible business need: more than 14 million attempted queries, returning data on 8.8 million people. While each query on its own fell within the company's permissions, the volume should have triggered an alert. However, as Jan points out, security monitoring did not detect and escalate it.

If the hacker’s account is true, the attack started with two basic failures: a former employee’s account was still active, and its password was 123456. The minister has acknowledged that security around the CPR system was not good enough.

Perimeter controls are built to keep outsiders out, and offer little protection when an attacker arrives with someone else's access. The control that matters is visibility: knowing which third parties and accounts hold access, and detecting when that access is used outside its expected pattern.

"You may have customers or suppliers that have access to systems in your environment," says Jan. "You want to make sure those systems are well monitored, and that you can react if something suspicious is happening, even when it comes from legitimate access."

An organisation’s own data faces the same risk when it is held in other organisations' systems, as with personal data in the CPR register. It is only as well protected as that party’s access controls and monitoring. In other words, security doesn’t stop at your door.

 

Detection

In the CPR case, the activity ran for about 10 days and was identified through billing rather than security monitoring. Companies pay for each CPR query, and the resulting invoice was large enough to prompt investigation. Each query was permitted, so none stood out on its own. It was the volume, well over a million queries a day from a smaller company, that gave the misuse away.

The same applies to any system that gives customers or suppliers access to data. This kind of misuse rarely shows in a single request. It shows in patterns, such as an account retrieving far more data than it normally does, or a high share of requests for records that don't exist, which is a common sign that someone is trying identifiers systematically. Jan's recommendation is to build detection rules that trigger on unusual data retrieval, regardless of whether the account is authorised.

"I think we all have some systems in our environment that probably aren't being monitored that well," says Jan. "It might be a good idea to find those systems and put the proper monitoring in place."

 

Implications for social engineering

The authorities have not confirmed who is behind the incident. The hacker who claims responsibility says they don’t plan to sell or leak the data, but there is no way to verify that. Organisations should nonetheless assume the data will be used for fraud and social engineering. Combined with other recent exposures, including a breach at the Technical University of Denmark disclosed on 2 October 2026, which may have exposed CPR numbers alongside work email addresses and employment details, it allows attackers to build credible pretexts using correct personal details.

One risk for organisations is attackers impersonating employees when they contact the IT service desk. Before resetting a password or MFA, service desk staff need to confirm that the caller is who they claim to be. Employees' CPR numbers are very likely included in the leak, so if a name and CPR number are enough to pass that check, an attacker can take over an employee's account.

Jan stresses the role of reporting. Users should report suspicious emails, texts and calls whether or not they engaged with them. "Not only if you clicked, but also if you just received it and didn't click," he says. Early reports give the security team time to act and stop a potential attack from escalating.

 

Recommendations

  • Identify processes that use a CPR number, name or address as proof of identity, and add an independent verification step.

  • Review service desk procedures for password and MFA resets.

  • Reinforce reporting of suspected phishing, including messages that weren't acted on.

  • Inventory third-party access to internal systems and confirm it is covered by monitoring.

  • Close accounts when people leave, and require strong passwords and MFA on all accounts with access to sensitive data.

  • Identify systems without 24/7 monitoring and close the gaps.

 

The importance of system monitoring

The misuse of CPR access was caught by accounting, not security monitoring, and only after about 10 days. By then, data on 8.8 million people had already been retrieved.

This highlights the need for close monitoring of critical infrastructure. Any system that gives customers or suppliers access to data carries the same risk. With Managed Detection and Response (MDR), analysts monitor activity around the clock and can respond as soon as something suspicious appears.

If you suspect misuse in your environment now, our Emergency Response team is available 24/7.

 

Stay updated

Sign up for our newsletter and get the latest cybersecurity analysis, reports and events from CSIS delivered straight to your inbox.

 

 

About CSIS

CSIS Security Group A/S is a leading European pure-play provider of tech-enabled cybersecurity and intelligence services. Operating 24/7, we deliver Managed Detection & Response, Incident Response, Security Consulting across all sectors, and provide a world-class threat intelligence capability through our SecAlliance brand. Accredited by organisations including CREST, we actively support global security initiatives to positively impact the cyber community.