VYPR
breachPublished Oct 7, 2026· 1 source

Danish CPR Register Breached via Supply Chain Attack, Exposing 8.8 Million Citizens' Data

A supply chain compromise allowed unauthorized access to Denmark's Central Register of Persons (CPR), exposing sensitive data for nearly all Danish citizens.

Denmark's Central Register of Persons (CPR) has suffered a significant data breach, with unauthorized actors gaining access to the personal information of approximately 8.8 million individuals. The incident, which occurred in September but was disclosed on October 5, involved a third-party company that had legitimate access to the CPR system. This breach highlights the pervasive and often underestimated risks associated with supply chain vulnerabilities, particularly when sensitive government databases are involved.

The compromised data includes names, addresses, dates of birth, marital status, family details, and the unique 10-digit CPR number for individuals, encompassing both living and deceased citizens. The Ministry of Research, Education and Digitalisation confirmed that the breach was detected after the CPR administration noticed "irregular behavior" in the system. The attackers exploited the access granted to a private Danish company, searching for information within the bounds of that company's authorized permissions, ultimately leading to a massive data exposure.

Experts have pointed to the centralized nature of national databases and the direct access granted to private entities as key factors enabling this breach. Dray Agha, senior manager of security operations at Huntress, stated that a single compromised supplier account can bypass an organization's core security controls, turning a legitimate connection into a significant data leak. This underscores the need for stringent access controls and continuous monitoring of third-party activities.

To mitigate such risks, security professionals emphasize the importance of limiting the scope of data external partners can access and implementing continuous monitoring to detect unusual search patterns. Michael Centrella, head of public policy at SecurityScorecard, argued that vendor risk management must evolve beyond static annual reviews, advocating for real-time monitoring of third-party access patterns and dynamic permission adjustments based on risk posture.

Recommendations for enhancing security include implementing stronger authentication methods, enforcing shorter session times, rate-limiting data requests, and establishing baselines for normal behavior to detect anomalies. Nathan Davies-Webb, principal consultant at Acumen Cyber, suggested these measures could significantly aid monitoring efforts and prevent large-scale data exfiltration.

In response to the breach, Danish authorities have urged citizens to be vigilant against phishing attempts, advising them never to divulge sensitive information if requested via email or phone, even if their CPR number is quoted. Individuals are encouraged to verify such requests through official channels and monitor their accounts for suspicious activity.

For future prevention, cybersecurity experts recommend individuals use unique passwords managed by a password manager, keep devices updated, and practice secure authentication habits. Organizations are advised to collect only necessary data, restrict access based on the principle of least privilege, and maintain robust monitoring for unusual activities. Regular supplier security reviews and well-rehearsed incident response plans are also crucial components of a comprehensive security strategy.

This incident serves as a stark reminder that even trusted suppliers' access requires the same level of scrutiny as an organization's internal systems. The breach of the CPR, a foundational database for Danish society, underscores the critical need for enhanced supply chain security measures to protect sensitive personal information from increasingly sophisticated cyber threats.

Synthesized by Vypr AI