The Danish CPR data breach highlights a vital business lesson: genuine personal details do not prove that a caller, email or payment request is legitimate.
Last updated: October 2026
Why accurate personal information is not proof of identity — and the financial controls every small business should reconsider.
The Danish CPR data breach has exposed a striking gap between the scale of sensitive information and the ordinary controls that should protect it. An unusually high bill helped alert authorities to suspicious CPR lookups concerning approximately 8.8 million people. Now a person claiming responsibility has told Politiken that a former employee’s leaked password — reportedly ‘123456’ — allowed access through a small company authorised to query the register. Authorities have not confirmed that account; importantly, it is not evidence that ‘123456’ was the national CPR register’s own password.
For small-business owners, the most useful lesson is not that everyone needs an expensive cybersecurity system tomorrow. It is simpler: genuine information can appear in fraudulent requests, and routine financial controls can help prevent a convincing message from turning into a costly mistake.

What happened in the Danish CPR data breach?
Denmark’s Central Person Register (Det Centrale Personregister, or CPR) stores core personal records for people who live or have lived in Denmark, including some who are now abroad or deceased. In early October 2026, the CPR administration announced that unauthorised parties had used a private company’s legitimate permission to search the system. Through that access, they obtained names, addresses, CPR numbers and related data concerning approximately 8.8 million registered people.
That figure is larger than Denmark’s current population because the register also includes historical records. The CPR administration stated that the unauthorised access did not include protected names and addresses of people with name and address protection. The company’s access was stopped, the incident was reported to Datatilsynet, and the police became involved.
The precise sequence of events, the people behind the activity and any subsequent misuse of the information remain matters for the authorities to investigate. Datatilsynet reported that a very large number of automated searches had apparently been used to identify valid CPR numbers. This is not the same as evidence that every affected person has experienced identity theft, or that criminals can now enter their MitID or bank account.
The reported ‘123456’ password: what is known and what remains unverified
A new detail has emerged in a Politiken report. A person claiming responsibility for the unauthorised lookups said they obtained access using a leaked password linked to a former employee of the smaller Danish company that could legitimately search the CPR register. According to the account, that password was ‘123456’. The person told the newspaper they then used two automated programs to collect and store records.
Ritzau reported that Politiken received a file containing CPR numbers and that an external IT-security specialist found the described method plausible. Nevertheless, an anonymous claim is not a completed forensic investigation. The individual’s identity, the precise entry point and the sequence of security failures have not been confirmed by the authorities. There is no verified basis for claiming that the central CPR system itself used ‘123456’ as its password.
If investigators confirm the account, several safeguards deserve scrutiny: why a former employee’s credentials remained usable, whether the account had multi-factor authentication, and why one set of credentials could apparently be used for such extensive activity. Even if the exact story changes, the business lesson holds. Password quality matters, but so do immediate offboarding, individual accounts, carefully restricted permissions, multi-factor authentication and unusual-activity alerts.
A business should not assume that ‘authorised to log in’ means ‘authorised to do anything’. An account normally used to view a small number of records should not be able to retrieve millions without meaningful monitoring. This is a third-party-access problem as much as a password problem, and it brings the incident directly into the world of small-business management.
The surprising part: an unusual invoice reportedly raised the alarm
At a press briefing, ministry department head Mikkel Leihardt described how the exceptionally large amount being billed for CPR lookups drew attention to an abnormal level of activity, according to Ritzau’s reporting. The company had lawful access for its ordinary work, but the volume of searches was far outside normal expectations.
The discovery story has a direct business lesson. A charge, invoice or pattern of activity that falls outside the usual range can be an early warning. It might reflect an innocent operational change, a process error or misuse. Someone must notice it, ask why it occurred and be able to escalate the question. Reconciliation, budget monitoring and review of exceptional transactions are therefore more than administrative housekeeping.
Of course, the invoice itself was not a substitute for technical security monitoring. Financial controls and cybersecurity controls complement each other; neither replaces the other.
Knowing someone’s real details does not make a request trustworthy
Imagine receiving a call from someone who knows your full name, address, CPR number and an apparently correct detail about an earlier interaction. It can feel reassuring. But accurate personal information is not a secure way to authenticate the caller. Datatilsynet has explicitly warned that knowledge of personal details does not prove a sender is who they claim to be.
The risk is not limited to sophisticated hacking. A fraudster can collect public facts, buy information, gain access to an email conversation or simply obtain a few convincing details from other sources. They can then use those details to create an urgent, believable story. This is often called social engineering: manipulating a person or a process rather than breaking through a technical system.
The central question for a business is therefore not just ‘Does this person know the right information?’ It is ‘Have we independently established that this person is authorised to request the action?’
Remember the fake Danish CVR registration emails?
We explored a related problem in our earlier article, ‘Beware of fake CVR renewal emails’. The fraudulent messages used the name Dansk Virksomhedsregister and demanded DKK 670 to keep a business registered. They often included the company’s real name, address, CVR number and other details available from the public Central Business Register (CVR). By filtering business registration dates, fraudsters could target new companies at a moment when unfamiliar administrative messages might seem plausible.
Those emails did not require a breach of the CVR database. The underlying records were publicly available; the deception was the invented payment demand. In a later warning, Erhvervsstyrelsen confirmed that messages of this kind were fraudulent and that CVR registration itself does not carry a recurring fee. There is an important nuance: certain registrations and company changes may legitimately involve fees, while smaller personally owned businesses (PMV) and voluntary associations may have a periodic renewal obligation that is free of charge. Legitimate notices are handled through official channels, including Digital Post.
The CVR scam and the CPR incident are separate events, and no connection between them has been established. We mention them together because they demonstrate the same practical weakness: legitimate-looking data can lend false authority to an illegitimate request.
When our own company was targeted by an impersonation email
A recent example came directly from our own inbox at Andreas Regnskab. We received messages that appeared to come from members of our team, using colleagues’ names that anyone could find on our website. The sender addresses belonged to external email accounts, not our company domain. The messages asked whether a particular amount of money was available in our business bank account that day, because a transfer needed to be made.
We asked who the payment should go to. The sender supplied bank details. We retained the full email exchange and the proposed recipient information, then passed the material to the relevant financial service provider so it could investigate. We do not know what conclusion that investigation reached, and we cannot assert how the receiving account was being used.
This was an impersonation attempt, not evidence that a colleague had actually requested the payment or that our own email system had been hacked. The names were genuine, the payment request was not. The lesson is straightforward: an email that uses the correct name of a director, colleague or accountant is not proof of authority. Verify financial instructions through a phone number or channel already known to your business, and do not let apparent urgency override payment checks.

Three realistic fraud scenarios for a small business
1. Your supplier ‘changes’ its bank account
A regular supplier emails a revised invoice with a new bank account. The message contains the right supplier name, previous invoice number and amount. Everything looks normal, except the payment details. Perhaps the supplier really did change banks. But the email thread could also have been compromised, or the sender could be impersonating a familiar contact. Before paying, call the supplier using a telephone number your company already trusts, and record the confirmation. Do not rely on the phone number in the suspicious message itself.
2. A ‘payroll update’ arrives with correct employee data
Someone asks payroll to change an employee’s bank details, quoting the employee’s name and CPR number. A rushed administrator may assume that those details prove the request is genuine. They do not. Use a secure employee self-service process, or verify the change through a previously established channel and document approval. Where possible, separate the person who enters a new bank account from the person who releases salary payments.
3. An urgent payment request impersonates a public authority
A message references a genuine CVR number and registered address, then claims an urgent fee, penalty or transfer is required. The timing may coincide with a real reporting deadline, making the story feel plausible. The safer response is to pause and check independently through Digital Post, the authority’s verified website or an established official contact. Even authentic-looking company details do not establish that a payment demand is legitimate.
These are illustrative examples, not reported outcomes of the CPR incident. Danish police already warn businesses about supplier-bank-detail fraud, fake invoices and messages impersonating management.
How businesses should verify identity now
Following the CPR incident, Styrelsen for Samfundssikkerhed and Sikkerdigital specifically advised companies and organisations to reconsider how they identify people. If a process currently treats a CPR number, name, address or date of birth as sufficient proof, it needs stronger checks — particularly before someone can access personal data, change payment information or reset an account.
The authorities suggest practical alternatives: ask the person to sign into an established self-service system such as one using MitID; send a one-time code to a contact detail already on record; call back on a number already registered; or use meaningful relationship-based verification, combined with other controls. For higher-risk transactions, manual review, a waiting period or in-person identification may be appropriate.
The key words are ‘already on record’ and ‘independent’. Sending a code to a new email address provided during the same suspicious call does not provide the same protection. Nor does asking only for an invoice number if an attacker has already gained access to the relevant email correspondence.
Third-party access: cybersecurity extends beyond your own office
The confirmed CPR incident involved misuse of a private company’s legitimate access to a national register. That is a useful reminder for any business using payroll software, bookkeeping platforms, banking integrations, customer-management systems, cloud providers or external advisers. Someone outside your organisation may have legitimate technical access to your data. If that access is compromised, your business may be affected even when your own staff followed their procedures.
Sikkerdigital offers a supplier-security toolkit for businesses and encourages managers to ask providers how they prevent unauthorised access, protect personal information, document their controls and divide responsibilities with customers. The questions need not become a lengthy questionnaire for every small subscription. Prioritise the systems holding salary details, personal records, payment information and administrator permissions.
In practice, keep a simple access register listing critical systems, named users or providers, the access level granted and who is responsible for reviewing it. When an employee, bookkeeper, consultant or external IT provider leaves, check all relevant systems: the finance platform, bank, email account, payroll, MitID Erhverv, shared folders, external dashboards and any API or integration credentials. Disable unnecessary accounts and sessions; changing a password alone may not close every way in.
This is not a theoretical concern. Datatilsynet has previously warned about breaches involving former staff whose access to email or customer systems remained active, and separately advises organisations to remove consultant and test accounts that are no longer required. A formal offboarding checklist is often an inexpensive and high-impact control.
A final question for the provider is worth asking: would anyone notice if an authorised account suddenly retrieved far more information than usual? Sensible access limits and usage alerts should complement human approval and payment monitoring. Smaller businesses can ask their IT partner to review these controls without trying to carry out a technical security audit themselves.
Seven controls worth implementing in your business
1. Verify changes to payment details outside the original message
Treat any request to change a supplier’s or employee’s bank account as a controlled process, even when the amount is small. Confirm through an established channel, record who checked and approved the change, and keep the evidence with the relevant accounting documentation. A simple checklist can work better than relying on someone’s memory.
2. Separate payment preparation from approval where possible
For companies with several employees, avoid giving a single person unchecked authority to create suppliers, edit their bank details and release payments. Even one independent approval for unusual or high-value transactions can reduce exposure. Sole proprietors cannot always separate duties, but can use a deliberate pause, a known-number call-back and a second review before a new payee is paid.
3. Review permissions across your finance systems
List who currently has access to the company bank, bookkeeping software, payroll solution, shared finance inbox and MitID Erhverv. Remove accounts that no longer need access, particularly after staff changes. Give users the lowest access level consistent with their role. Datatilsynet’s guidance on access management emphasises both limiting permissions and periodically checking that they remain appropriate.
4. Protect email accounts with strong sign-in and good oversight
A compromised email account can make a fraudulent invoice look exceptionally credible, because the attacker may reply inside an existing conversation. Enable multi-factor authentication, use separate accounts rather than shared passwords where possible, and review unexpected email forwarding rules or unusual account activity. Ensure employees know how to report suspicious messages without fearing criticism.
5. Make urgent requests subject to extra scrutiny, not less
Fraud attempts often combine urgency, confidentiality and a request to skip normal procedures. Define who can approve exceptions and how those exceptions are recorded. A CEO or client who genuinely needs an urgent payment can still be contacted using a known number. A strong process should survive holiday cover, staff absence and busy payroll days.
6. Investigate unusual transactions, charges and volumes
Regular bank reconciliation and review of supplier balances remain valuable. Look for duplicate invoices, unfamiliar recipients, unusual fees, changed account information and payment patterns that no longer fit the business. For companies with large volumes of transactions or API-based services, set thresholds or alerts for extraordinary usage as well. The CPR billing story illustrates why small anomalies should have a clear route to investigation.
7. Know what to do if something goes wrong
Choose in advance who contacts the bank, who handles affected accounts, who preserves records and who calls the IT provider. Keep contact details available even if the company email is unavailable. Test critical backups and decide who can approve an emergency change to a payment process. An incident plan can be short; the important thing is that people can use it under pressure.
A ten-minute fraud-prevention self-check
- Could anyone change supplier bank details in our records without an independent confirmation?
- Do we verify employee payment changes through a previously established secure channel?
- Do we know who can access our banking, email, bookkeeping, payroll and MitID Erhverv systems?
- Have we removed old user accounts and reviewed permissions after staff or adviser changes?
- Is multi-factor authentication enabled on business-critical accounts?
- Do unusual payments, fees and new beneficiaries trigger a review?
- Does every employee know what to do with a suspicious request or invoice?
- Would we know whom to call immediately if a fraudulent transfer had been made?
If the answer to several questions is ‘not sure’, start with payment-detail verification and access reviews. Two or three reliable controls, followed consistently, are more useful than a lengthy security policy that nobody follows.
What should individuals do after the CPR data breach?
Datatilsynet’s advice is measured: stay attentive, but do not assume that every record accessed will be misused. Treat unexpected emails, calls and text messages cautiously, especially when the sender cites accurate personal details. Find the organisation’s contact information yourself and do not disclose MitID codes, passwords, payment-card details or other secrets in response to unsolicited contact.
If you have used your CPR number, or part of it, as a password or another login secret, change that credential. Otherwise, the CPR incident alone does not mean you must reset every unrelated password. Watch for activity you do not recognise — such as unexplained subscriptions, credit applications or account changes — and respond promptly to concrete warning signs.
Sikkerdigital advises considering a credit warning (kreditadvarsel) through borger.dk when there is specific concern about misuse of a CPR number. Such a warning can make it more difficult for you to obtain legitimate credit too, so it should be a considered step rather than an automatic reaction for everyone. For guidance, use official Sikkerdigital resources or the Danish Cyberhotline.
What if your company receives a suspicious request — or has already paid?
Before payment: stop the action, preserve the original message, and verify the request via a trusted alternative channel. Do not confirm a bank-detail change by replying to the same potentially compromised email thread. Ask a colleague or adviser for a second assessment when necessary.
After a suspected fraudulent payment: contact your bank immediately and ask whether the transfer can be stopped or recalled. Save relevant messages, invoices and transaction records. Follow the police’s reporting guidance. If you suspect that accounts or personal information inside your company have been compromised, involve the relevant technical and data-protection specialists promptly so any incident-response and notification obligations can be assessed.

Where your bookkeeper fits into the picture
Bookkeepers and accountants see an unusual part of a company’s daily activity: invoices, payment runs, salary changes, bank reconciliation and patterns in the accounts. That makes financial professionals useful participants in fraud prevention. They can help establish documentation requirements, question unusual entries and improve controls around approvals and reconciliation.
But those responsibilities have limits. A bookkeeping firm cannot guarantee protection from a cyberattack or replace a specialist responsible for network security, forensic investigation or legal advice on a data breach. The strongest approach is cooperation among management, finance, IT and — when appropriate — legal or privacy advisers.
The real lesson: verify the request, not just the details
The Danish CPR incident and the earlier fake CVR renewal emails are very different stories. One concerns misuse of authorised access to personal records; the other exploited publicly available business records to make a fake fee look plausible. Their shared lesson is worth remembering: accurate names, numbers and addresses can make a message persuasive without making it trustworthy.
For most small businesses, improving security can begin with an ordinary question: ‘Who checked this, and how?’ A well-designed payment or identity-verification step will not solve every cybersecurity problem. It can, however, prevent a convincing message from becoming an avoidable financial loss.
How Andreas Regnskab can help
If you are uncertain about an unusual invoice, a supplier’s changed payment details or a financial request that does not look right, we can help you review the accounting documentation and identify what needs independent confirmation. We also help businesses strengthen routine bookkeeping and financial-control processes. For specialist IT security or legal matters, involve a qualified provider.
Want to strengthen your financial controls?
We can help you review unusual invoices, payment documentation and practical bookkeeping controls — and identify when specialist IT advice is needed.
Frequently asked questions
That has not been established. A person claiming responsibility told Politiken that a former employee’s leaked password, reportedly ‘123456’, enabled access through a private Danish company with lawful permission to query the CPR system. Authorities have not confirmed the person’s identity or the account. The allegation must not be confused with a verified password for the central CPR registry itself.
Not simply because they know your CPR number, name or address. Access to CPR data is not the same as access to MitID credentials. Never approve an unexpected MitID request or disclose authentication codes.
Not necessarily. CPR numbers may still have legitimate administrative uses, including in payroll. The important change is not to use a CPR number as sufficient proof of identity when granting access to information or authorising a sensitive request.
No connection has been established. The fake CVR emails relied on public company details, whereas the CPR incident involved unauthorised access through a company’s permitted CPR search facility. They illustrate similar risks from different sources.
The authorities have not advised everyone to reset all passwords solely because of this incident. Change credentials that are known to be compromised, and change any password or login secret that uses all or part of a CPR number. Use unique passwords and multi-factor authentication as general good practice.
Introduce a documented, independent check before changing payment instructions. Then review user access and identity-verification procedures. The right priority depends on your operations, but those two areas directly address common opportunities for fraud.
Sources and further reading
Official guidance
- CPR administration — official notice on unauthorised access
https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger - Ministry of Research, Education and Digitalisation — incident facts
https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/ - Datatilsynet — investigation and guidance on the CPR incident
https://www.datatilsynet.dk/presse-og-nyheder/nyhedsarkiv/2026/okt/datatilsynet-er-opmaerksom-paa-sag-om-opslag-i-cpr
https://www.datatilsynet.dk/presse-og-nyheder/nyhedsarkiv/2026/okt/cpr-sagen-det-kan-du-goere-hvis-du-er-bekymret-for-dine-personoplysninger - Styrelsen for Samfundssikkerhed and Sikkerdigital — identity checks and citizen guidance
https://via.ritzau.dk/pressemeddelelse/15209445/myndigheder-organisationer-og-virksomheder-bor-supplere-deres-identitetskontrol-efter-laek-fra-cpr-registeret
https://www.sikkerdigital.dk/borger/digital-svindel/uvedkommende-har-faaet-adgang-til-borgeres-cpr-oplysninger-saadan-skal-du-forholde-dig - Danish Business Authority — warning about the fake company-register fee
https://erhvervsstyrelsen.dk/har-du-et-cvr-nummer-saa-pas-paa-mails-fra-falsk-virksomhedsregister - Danish Police — advice on protecting companies against fraud
https://politi.dk/anmeld-kriminalitet/digital-kriminalitet/undgaa-at-din-virksomhed-eller-forening-bliver-svindlet - Datatilsynet — access rights according to business need
https://www.datatilsynet.dk/regler-og-vejledning/behandlingssikkerhed/katalog-over-foranstaltninger/adgangsrettigheder-efter-behov - Datatilsynet — removing former employees’ access
https://www.datatilsynet.dk/regler-og-vejledning/behandlingssikkerhed/ugens-sikkerhedstip/2023/nov/hold-styr-paa-tidligere-medarbejderes-adgang - Datatilsynet — former staff, consultant and test access
https://www.datatilsynet.dk/regler-og-vejledning/behandlingssikkerhed/ugens-sikkerhedstip/2025/jan/husk-ogsaa-at-nedlaegge-konsulent-og-testadgange - Sikkerdigital — discussing IT security with suppliers
https://www.sikkerdigital.dk/virksomhed/leder/leverandoerpakken
Reporting and earlier Andreas Regnskab article
- Ritzau report carried by The Copenhagen Post — unusually large bill
https://cphpost.dk/2026-10-06/news/round-up/large-search-bill-alerted-danish-authorities-to-breach-of-8-8-million-cpr-records/ - Andreas Regnskab — earlier article about fake CVR renewal emails
https://andreasregnskab.dk/news/beware-of-fake-cvr-renewal-emails-heres-how-to-spot-and-avoid-the-scam/ - Ritzau / The Copenhagen Post — Politiken interview and the reported ‘123456’ password claim
https://cphpost.dk/2026-10-09/news/round-up/hacker-claims-simple-password-allowed-access-to-8-8-million-danish-cpr-numbers/
Disclaimer
This article provides general information about fraud awareness, identity verification and business financial controls. It is not tailored legal, data-protection or technical cybersecurity advice. The correct response depends on your circumstances. Official guidance and investigation findings may change as the CPR case develops.
