@pollar.news: On 5 October 2026, Denmark's Ministry of Higher Education and Science said someone had gained unauthorised access to CPR numbers and other details in about 8.8 million records of the CPR register. The register holds about 11 million entries, including people who have died or moved abroad. Denmark has about 6 million residents. Protected names and addresses were not included. Which entries were reached has not been published. The access came through a small Danish company with a legal right to search the register, for people it had identified in advance. At a briefing on 6 October, the ministry said well over 14 million lookups were tried in about ten days and 8.8 million returned a record. An unusually large bill drew attention. The register's report to the data protection authority describes automated lookups made to identify valid CPR numbers. Police say it is too early to say who is behind it or how it was done, and no one has been charged. The company has not been named. The minister, Christina Egelund, said security around its access had not been good enough. A CPR number starts with a birth date. For any one birth date there are 10,000 possible serials. On 6 October, the Danish Resilience Agency advised basing identity checks, as a rule, on something other than CPR data, such as a MitID login or a code sent to a phone already on file. Danish law allows a new number in special cases after identity misuse. Asked whether anyone will get one after this, the minister said it is too early to say. Sources: Ministry of Higher Education and Science; Datatilsynet; Danish Resilience Agency; Danish police (NSK); CPR Act; cpr.dk; Statistics Denmark; TV 2; DR; Ritzau. Cover: Danish health card, photo: Pieceofmetalwork, CC BY-SA 4.0. #Denmark #cybersecurity #identitytheft #privacy #news
pollar.news
Region: DE
Tuesday 06 October 2026 15:17:40 GMT
Music
Download
Comments
Aesou :
We have a similar number system in Norway but it's never been used as any kind of authentication, just identification. The number is simply just there to have a unique identifier for each person (since names are not necessarily unique). As far as I know Denmark is quite similar, so this security breach is likely more an issue about technical security, i.e. fear of DDOS attacks and such rather than a fear of what the numbers can be used for.
2026-10-07 04:07:01
3
peeps :
my bet is on openai
2026-10-06 18:29:07
387
Dr. Bjælke :
As a Dane, this was explained much better, than any Danish media outlet.
2026-10-06 16:33:54
7674
Chaotic Alex :
It’s astonishing that in this day and age we still treat single string of numbers (like SSN in US, CPR in Denmark or PESEL in Poland) as sufficient form of identification and confirmation of someone’s identity.
2026-10-06 15:54:46
510
Mads :
yeah but its not a code for anything. sooo they cant use it for much🤣
2026-10-07 06:29:54
1
Nicso :
Part of the problem is that government institutions have a frame of sallary decided from high up. These sallaries are quite low compared to similar private jobs. The effect is that many high skilled people are not working in these institutions
2026-10-07 06:34:48
0
linnihoudini✨ :
this is going to sound bad, but it made me feel grateful for having a stalker 15 years ago, cause my name and adress is protected.
2026-10-07 05:31:09
4
Slacker :
In Sweden you can look up people’s CPR online for free. You can’t really do much with just the CPR number nowadays.
2026-10-06 17:14:32
2249
Grafik Pat :
The fact that there is no alert system that a company can pull over a million requests per day is just plain stupid
2026-10-06 20:48:38
719
Izabella Andersson23 :
they can't do shit without MITID
2026-10-07 06:57:47
4
Fin :
As someone who works in tech, there’s so many simple ways to detect this sort of thing. Basic security
2026-10-06 17:08:24
1192
Z1no :
så længe det ikke er mit uni-login
2026-10-06 20:22:06
833
coco gesundheit official :
so a social security number
2026-10-07 03:17:58
0
24 videos :
and they are still pushing ID age verification
2026-10-06 15:43:27
411
𝓜𝓲𝓻𝓪🦢 :
Chat er vi cooked
2026-10-06 17:48:04
358
Taso :
it should be criminal for government apps not have alerting functionality. It's very basic security to be altered by such malicious activity near real time
2026-10-06 19:32:30
80
𝒻𝒜𝒰𝒩𝒜🪽 :
So it’s basically all of us
2026-10-06 17:44:38
730
Adelstern :
We have them in Romania too, they're called CNP (Cod Numeric Personal). You need your CNP for everything: bank account, tenancy agreement, contracts, doctor appointments, all sorts of appointments, et cetera.
2026-10-06 17:07:04
58
Aw1tysm :
Kommer det her til at påvirke Netto too good to go priser ?
2026-10-06 17:45:07
2010
Bibi :
We are cooked
2026-10-06 19:28:49
111
Ghost :
Godnat💋
2026-10-06 21:18:52
88
OhReally? :
so there weren't basic rate limits and alerts for high volume queries?
2026-10-06 19:02:43
135
Daniel :
it really isnt that big of a deal, since you cant do anything with that info unless they gain access to your mitid.
2026-10-06 17:38:01
17
Marc L :
honestly you can't really use that data for much. So we don't care much about this here in Denmark. But the press loves this and the government can now call for more control
2026-10-06 22:25:41
8
jade.sylvie :
God, can you imagine how unbearable that company’s IT security training is going to be in response to this??
2026-10-06 21:23:19
31
To see more videos from user @pollar.news, please go to the Tikwm
homepage.