- Published on
Denmark's Population Register Breach: What Can Iceland Learn?
- Authors

- Name
- Gísli Hrafn Halldórsson
On 5 October 2026, Danish authorities announced a major security incident involving the country’s Central Person Register (CPR), which exposed personal information associated with approximately 8.8 million registered individuals.1
The exposed information included names, addresses, and CPR identification numbers (comparable to the Icelandic kennitala). The system contains records for approximately 11 million individuals. This exceeds Denmark’s current population of around 6 million because it also includes deceased individuals and people who have emigrated.
This data breach raises interesting and important questions regarding the security of national population registers; which is especially relevant in countries such as Iceland, where similar systems are fundamental to everyday life (Iceland.is rafræn skilríki, among others).
How did it happen?
Interestingly, the attackers did not require direct access to the central registry; rather, they exploited the legitimate access of a private Danish company to the CPR system. According to Denmark’s Data Protection Agency (Datatilsynet), an abnormally high number of automated queries were made, apparently attempting to identify valid CPR numbers.2 Subsequent reporting revealed that approximately 14 million queries were made over roughly ten days in September.3
Most surprisingly, the activity reportedly came to the authorities’ attention not through a normal security alert, but instead because of an abnormally large invoice generated by these queries.3
On 9 October 2026, the Danish IT company Pays ApS confirmed that its access had been misused. The newspaper Politiken also reported that several company accounts had used the password 123456, while an individual claiming responsibility described accessing the system using leaked credentials from a former employee.4
The precise circumstances of the intrusion and the attack methods used remain under investigation at the time of writing.
What about Iceland?
Iceland operates a comparable national population register, maintained by Þjóðskrá Íslands (Registers Iceland).
Like the Danish CPR system, Iceland’s population register contains personal information, including names, addresses, national identification numbers (the kennitala), and other registration details.
Similarly, Icelandic legislation allows authorized third parties to access population-register information.
Under Article 12 of Iceland’s Act on the Registration of Individuals (No. 140/2019), sharing information from the population register requires authorization and may be conducted through contractual arrangements with approved intermediaries. The law generally doesn’t allow sharing the entire register, but there are some specific exceptions.5
This does not imply that Iceland’s population register suffers from the same vulnerabilities as Denmark’s. Rather, the incident in Denmark demonstrates a security problem relevant to any system that provides external organizations access to large amounts of personal information.
Just securing the central database isn’t enough if authorized access to that database can be misused.
For Iceland, the incident raises several general questions worth considering:
- How effectively can abnormal access patterns be detected?
- Are organizations restricted to accessing only the information they actually need?
- Could it be possible to limit automated queries to prevent large-scale data collection?
- What safeguards are in place if an authorized organization’s credentials are compromised?
The risks of exposed personal information
National identification numbers are particularly problematic when exposed because they are persistent identifiers that cannot easily be replaced.
Although knowing someone’s CPR number/kennitala does not automatically grant access to their accounts, if a malicious actor were to combine that information with names and addresses, it could make their phishing attempts and identity impersonation much more convincing.
The Danish authorities have warned citizens not to disclose confidential information to callers or email senders, even when those individuals appear to know their personal details.1 The same principle applies in Iceland, where CERT-IS has previously warned about phishing campaigns that attempt to trick individuals into authorizing actions using their electronic identification credentials.6
Lessons from the breach
The incident in Denmark shows the importance of applying cybersecurity principles beyond just the boundaries of an individual organization.
The risks associated with third-party access can be mitigated with things such as strong authentication, appropriately restricted access permissions, rate limiting, and monitoring for unusual activity.
Perhaps the most important lesson is that legitimate access does not necessarily mean legitimate activity. Proper authorization depends on proper authentication.
As national services become increasingly interconnected, the security of sensitive information depends not only on the organizations maintaining that information, but also on everyone authorized to access it.
Footnotes
“Omfattende uautoriseret adgang til borgeres CPR-oplysninger” [Widespread unauthorized access to citizens’ CPR information], Danish Ministry of Science, Higher Education and Digital Affairs. Accessed: Oct. 11, 2026. [Online]. Available: https://fudm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/ ↩ ↩2
“Datatilsynet er opmærksom på sag om opslag i CPR” [The Danish Data Protection Agency is aware of the case regarding the publication in the CPR.]. Accessed: Oct. 11, 2026. [Online]. Available: https://www.datatilsynet.dk/presse-og-nyheder/nyhedsarkiv/2026/okt/datatilsynet-er-opmaerksom-paa-sag-om-opslag-i-cpr ↩
Ritzau, “Large search bill alerted Danish authorities to breach of 8.8 million CPR records,” The Copenhagen Post. Accessed: Oct. 11, 2026. [Online]. Available: https://cphpost.dk/2026-10-06/general/large-search-bill-alerted-danish-authorities-to-breach-of-8-8-million-cpr-records/ ↩ ↩2
Ritzau, “Medie: Tre profiler hos virksomhed i datalæksag brugte koden 123456.” [Media: Three profiles at company in data breach case used the code “123456”]. Accessed: Oct. 11, 2026. [Online]. Available: https://www.dknyt.dk/ritzau/9c1ce2f4-fa07-4af8-a69d-e7cbd4c66641 ↩
“140/2019: Lög um skráningu einstaklinga” [140/2019: Act on the Registration of Individuals], Alþingi. Accessed: Oct. 11, 2026. [Online]. Available: https://www.althingi.is/lagas/nuna/2019140.html ↩
“CERT-IS varar við svikaherferðum sem beinast gegn rafrænum skilríkjum” [CERT-IS warns of fraud campaigns targeting electronic IDs], CERT-IS. Accessed: Oct. 11, 2026. [Online]. Available: https://cert.is/frettasafn/cert-is-varar-vid-svikaherferdum-sem-beinast-gegn-rafraenum-skilrikjum/ ↩
