
The CPR Number Was Never a Secret

- On 5 October the ministry responsible for CPR disclosed that someone had used a private company's lawful access to the register to collect names, addresses and CPR numbers, among other details, for about 8.8 million people. An unusually large bill caught it rather than an alarm.
- An identifier cannot also be a secret. Denmark calls the CPR number confidential in law, yet prints a dead person's number in Statstidende, and issues a living person a new number only in special cases. Styrelsen for Samfundssikkerhed now advises against releasing sensitive information on CPR data alone.
- With most of the numbers already out, I think we are forced to treat CPR numbers as open: assumed known to anyone, and never enough on their own for a service to confirm who someone is or to release anything sensitive. The register still holds nearly everyone's name and address, so every account with access needs a second factor, and each firm needs a cap on its lookups with an alarm well below it.
On 5 October the ministry responsible for the Central Person Register announced that unauthorised parties had collected names, addresses and CPR numbers, among other details, for about 8.8 million people. The register holds around 11 million, counting the living and the dead, so this is most of it. The names and addresses of people with name and address protection were not collected.
8.8M
of the roughly 11 million people registered in CPR, living, dead and emigrated, had their CPR data collected in September.
Omfattende uautoriseret adgang til borgeres CPR-oplysninger — The ministry’s announcement: a private Danish company’s lawful access to CPR was misused to collect names, addresses and CPR numbers, among other details, of about 8.8 million registered people, within the information private companies have access to; the names and addresses of people with name and address protection were not included, and the irregular activity in September was noticed on 2 October.
Professor: ‘Det største brud nogensinde mod det danske CPR-register’ — DR’s interview with Professor Jens Myrup Pedersen, who calls it the largest breach ever against the register: his view that nobody should have access to more than they need, and that unusually many lookups should trigger alarms or blocks, and his conclusion that Danes can no longer assume others do not know their CPR number. The article also gives the register’s size as about 11 million people.
A Lawful Door, Used at Scale
Nothing published so far suggests a flaw in the register itself. Someone misused the lawful access of a small private Danish company. The CPR Act lets firms look up the current name and address of people they have already identified, and according to the ministry the extraction stayed within what such firms can see. Jens Myrup Pedersen, a professor of cyber security, called it the largest breach ever against the register.
According to DR, neither an automatic alarm nor a spot check caught it. Firms pay for each lookup, and what gave the extraction away was the company’s unusually large bill at the end of September. TV 2 reported that about 14 million searches went through the firm’s access, far more than it has customers.
Sådan blev CPR-databrud opdaget: ‘Det er ret chokerende’ — DR’s report that neither automatic alarms nor spot checks led to the discovery, but an unusually expensive bill to a smaller Danish company at the end of September, since firms pay for each lookup; it carries Jan Kaastrup of CSIS comparing a CPR number that cannot be replaced to a single password for life that works across a great many systems.
Nye detaljer om cpr-skandale — hacker var over alle bjerge — TV 2’s report, from a press conference, that about 14 million searches on CPR numbers went through the smaller company’s lawful access to the CPR system, a number far beyond the company’s customer base.
Bekendtgørelse af lov om Det Centrale Personregister — The CPR Act, §§ 38, 39 and 42: businesses may receive CPR information, including current name and address unless these are protected, about a larger, delimited group of people they have already identified individually, or make single electronic lookups in CPR about a person they have identified in advance.
On 8 October Politiken reported that an anonymous hacker said they were behind the extraction. The hacker says the attack began on 11 September with a leaked password belonging to a former employee of the company. It was 123456, and two homemade programs then looked up CPR data and stored the results elsewhere. The claim is unconfirmed. Emil Hørning of Defend Denmark examined a file the hacker shared with Politiken and judged it likely that the hacker was telling the truth. If the claim holds, the route to CPR started with a former employee’s password of six digits in sequence.
Separately, the minister has acknowledged in writing that security around the CPR system has not been good enough, and says that unauthorised parties can no longer get into the system by similar means and that a security review has been requested.
It-kriminel hævder at stå bag CPR-angreb: Kom ind via simpelt password — Ritzau’s account of the hacker’s unverified claim to Politiken: access from 11 September that began with the password 123456, obtained from a former employee of a smaller Danish company with access to the register, two homemade programs to find and store the data, Emil Hørning’s assessment that the claim is likely true, and the minister’s written reply acknowledging that security around CPR has not been good enough, that unauthorised parties can no longer get into the system by similar means and that a security review has been requested.
An Identifier Cannot Be a Secret
Officially, the CPR number is confidential. The Data Protection Authority describes it as confidential information, regulated separately in the Data Protection Act, and the Act forbids private parties to publish one without consent. It also lets businesses pass CPR numbers on where that is a natural part of their work and essential for identifying a person uniquely. In law, confidential means withheld from the public, not hidden from the parties that rely on the number, so the rules do not contradict each other. The trouble starts when services treat knowing the number as proof of who you are, because then a number shared that widely is asked to work as a secret. That is what I meant in Digitalisation: Lost Privacy by Design when I called it the closest thing Denmark has to a master key to a person’s identity.
An identifier has to be shared with every party that relies on it, and a secret cannot be shared with all of them. In practice the identifier wins, and the number is copied into every system that needs one, so it is only as safe as the weakest system that holds it, the register included.
Hvad er personoplysninger? — The Data Protection Authority’s guidance that the CPR number is confidential information, regulated separately in the Data Protection Act, and that information is confidential where society generally expects it to be withheld from public knowledge.
Bekendtgørelse af lov om supplerende bestemmelser til forordning om beskyttelse af fysiske personer i forbindelse med behandling af personoplysninger og om fri udveksling af sådanne oplysninger (databeskyttelsesloven) — The Data Protection Act, § 11: among its grounds, private parties may process CPR numbers where legislation provides for it, with consent, for research or statistics, or to disclose them where that is a natural part of normal business and essential for identifying the person uniquely; § 11(3) forbids them to publish a CPR number without consent.
The state goes further and publishes it. Statstidende, the state gazette, prints the deceased’s number in the notice to an estate’s creditors, because the Estate Administration Act requires it. A person whose number has leaked cannot simply be given another, since the CPR office assigns new numbers only in special cases and normally only where documented misuse has gone on over a period. Jan Kaastrup of CSIS compared this to having one password for the rest of your life that can never be changed and works across a great many systems. The minister has not ruled out new numbers, but says it is too early to tell whether anyone will need one. For someone whose number is being misused, a new number would help. It would not change what the number is, because the replacement is handed to the same places and can leak from any of them, or from the register again.
Pedersen said the time when Danes can assume others do not know their CPR number has to be over. On 6 October Styrelsen for Samfundssikkerhed urged authorities, organisations and businesses not to release sensitive information on the strength of CPR data alone, and to check identity another way: a MitID login, a one-time code, a call-back to a number already on file or a visit in person with identification. The advice is needed because services, and many of us, have taken CPR data as proof of identity.
Bekendtgørelse af lov om skifte af dødsboer — The Estate Administration Act, § 81: the notice calling for an estate’s creditors is mandatory when an estate is settled or passed to a surviving spouse, and under § 81(3)(1) the notice, published in Statstidende, must state the deceased’s name, address, CPR number and date of death.
Identitetsmisbrug — The CPR office’s guidance that a new personal number is assigned only in special cases, on written request with documentation, that it will normally require misuse on more than one occasion over a period, and that a stolen wallet and fear of future misuse are not enough on their own.
Minister efter orientering: Udelukker ikke nye CPR-numre efter læk — Ritzau’s report that the minister does not rule out new CPR numbers: it is too early to say whether anyone will need one, and the security review of the whole CPR system, which has no timeline, will decide what changes follow.
Myndigheder, organisationer og virksomheder bør supplere deres identitetskontrol efter læk fra CPR-registeret — The agency’s guidance that sensitive information should not be released on the basis of CPR information alone, that identity checks should as a rule rest on something other than CPR data, and its list of alternatives, from a MitID login and one-time codes to call-backs and checks in person.
Identifier or Password
In The Illusion of Delete I wrote about how we ask systems to do two fair things that cannot both be true at once. The CPR number is the same problem. Denmark has let it be an identifier and a password at the same time: shared with every employer, bank and company that needs to tell us apart, and still accepted by many services as proof that we are who we say we are. The register is where those numbers are kept, and one company’s lawful access reached 80 percent of the people in it.
Private access to CPR exists for good reasons, such as keeping a customer’s address up to date, and I would keep it. Whatever the way in turns out to be, the first fixes are the ordinary ones: a second factor on every account with access, and accounts closed when their owners leave. They decide who can log in, but they do nothing once someone has, whether that is an attacker or an employee with a reason of their own.
Each firm’s lawful purpose also implies how many people it needs to look up. The CPR Act already limits a firm’s lookups to people it has identified in advance, but about 14 million searches went through this small firm’s access before anyone noticed, so a legal limit on lookups is not matched by a technical one unless someone builds it. A cap set from that purpose, with an alarm well below it, much as Pedersen proposed, would watch what an account does, whoever logged in. A bank with a million customers would need a cap of a million, so a cap would do most for small firms like this one. It would also protect the names and addresses still in the register, which are worth protecting whatever becomes of the number.
A cap cannot take back the numbers that have already left. With 8.8 million of them out, names and addresses attached, the number’s legal confidentiality protects little now. The ban on publishing it still matters, because it keeps the leaked numbers from being republished freely as a list anyone can search. Moving every check off CPR data has a cost, and it falls hardest on people without MitID, who will meet more call-backs and more visits in person. Even so, I think this forces us to treat CPR numbers as open: numbers we assume anyone might know, and which no bank, authority or employer should treat as enough, on its own, to confirm who we are or to release anything sensitive.
The views and perspectives expressed here are the author's own and do not represent any employer or affiliated organisation. The writing draws on public sources and the author's own experience, never on confidential information.
These briefs are written with the help of AI: it finds sources, drafts and checks. Every choice it makes in a draft is one the author reviews, and the ideas, the judgement and the final words are the author's own. What it does, and what it does not, is set out in the Authorship Was Never the Typing brief.
Niclas Hedam
PhD, Computer Science
Niclas Hedam holds a PhD in Computer Science from the IT University of Copenhagen. He is passionate about educating others on the importance of safeguarding personal information online.

