What occurred during the 8.8 million CPR breach?
In autumn 2026, Denmark faced the largest data security breach in its national identity history. Unauthorized actors accessed records covering approximately 8.8 million individuals in the Central Person Register (CPR).
The unauthorized activity occurred through misuse of a private Danish enterprise's legitimate search access to the CPR infrastructure over a ten-day period in September before being detected by administration staff.
The Minister for Digital Affairs characterized the breach as deeply serious, and the matter is under active criminal investigation by the National Special Crime unit (NSK) and reported to the Danish Data Protection Agency (Datatilsynet).
How criminals exploit leaked identification numbers
While Danish financial systems require strong MitID two-factor authentication to disburse loans or transfer funds, leaked CPR numbers and addresses provide attackers with powerful social engineering leverage.
Fraudsters impersonate banks, law enforcement, or government agencies. By reciting the victim's exact CPR number and home address over the phone, they establish immediate credibility, then manipulate the victim into transferring funds to an alleged »safe account« or approving a fraudulent MitID session.
Why CPR numbers can no longer serve as security questions
Customer service operations have historically asked callers for their CPR number and address to confirm identity. Following this breach, any malicious actor can answer these questions flawlessly.
Relying on spoken personal identification numbers exposes businesses to severe compliance penalties and unauthorized account takeover.
Official guidelines from Sikkerdigital.dk
The Danish authorities recommend activating Credit Warning on borger.dk, hanging up on unexpected calls from purported authorities, and never approving MitID requests at the behest of an inbound caller.
Two-way cryptographic verification with KvikID
KvikID replaces fragile verbal screening with instantaneous MitID identity verification. The company simply enters the person's CPR number into the KvikID platform. The individual immediately receives a notification in their MitID app on their mobile phone, swipes to approve, and their identity is verified in seconds without exposing sensitive details aloud.