Stolen CPR data raises risk of official phishing scams in Denmark
Data covering 8.8 million people in Denmark was compromised, enabling scammers to craft realistic phishing messages.
2026年10月5日
/ DANGDI / DANGDI / DANGDI /About 8.8 million people in Denmark have had their CPR data accessed without authorization. A cybersecurity expert warns that this stolen data could make phishing attacks much more convincing.
Denmark's Digitalization Ministry announced the breach on Monday. The compromised database includes names, addresses, and CPR numbers. It affects current, former, and deceased residents.
CPR numbers serve as Denmark's official personal identification. Scammers can combine your CPR number with your name and address. They can send fake messages that look like official notices from Danish authorities.
Aarhus University professor Jens Myrup Pedersen explained the risks to CPH Post. He noted that more personal details allow criminals to create far more realistic scams.
Pedersen said a CPR number alone should not allow criminals to obtain loans. Service providers cannot verify identity solely based on a CPR number. However, stolen data might be sold or combined with public online photos.
The professor described this breach as unusually extensive and deliberate. It differs from a 2015 incident where records were accidentally sent to a visa firm. Residents across Denmark should stay alert for suspicious digital messages.
Source: The Copenhagen Post


