Jessica Entwistle
October 6 2026
Unauthorised parties accessed names, addresses and personal identification numbers for approximately 8.8 million people in Denmark's Central Person Register (CPR), including living and deceased individuals, according to TechCrunch reporting on 5 October 2026. The breach occurred through a private Danish company's legitimate access rights to the national database. Denmark's digitisation ministry confirmed that attackers exploited lawful access credentials belonging to a commercial organisation that held authorised query rights to the CPR. The incident affects the entire Danish population and individuals registered historically, making it one of the largest government data exposures in recent European history.
This incident illustrates the systemic risk created when third parties hold privileged access to sensitive databases, particularly where those access rights are broad and difficult to monitor in real time. Many UK businesses grant similar access to partners, suppliers, managed service providers and integration platforms that query internal systems or customer databases. The Danish breach demonstrates that even lawful access can become an attack vector when credentials are compromised, misused or inadequately monitored. This is particularly relevant for organisations in healthcare, finance, legal services and local government, where third-party access to sensitive records is common and often necessary for operational reasons. The scale of the breach also highlights the potential impact when access controls fail: a single compromised credential with broad query rights can expose millions of records before the activity is detected.
UK businesses should review how third-party access to sensitive systems is governed, monitored and scoped. Consider whether privileged access is limited to the minimum necessary for operational purposes, whether query activity is logged comprehensively and reviewed regularly, and whether access can be revoked quickly if misuse is detected. Organisations should also assess whether similar access arrangements exist with partners or suppliers who hold credentials to internal databases, identity systems or customer records. This is an opportunity to ensure that third-party access is subject to the same governance, monitoring and review processes as internal privileged accounts, and that responsibility for oversight is clearly assigned. Where third-party access is essential, consider whether technical controls such as query rate limiting, anomaly detection or just-in-time access provisioning could reduce the risk of misuse.
Source: TechCrunch