
CPR Data Breach in Denmark: How to Protect Yourself Against Scams
Your CPR number is an identifier – it is not a password. Knowing your CPR number, name or address does not prove that a caller is genuine.
Do not pay. Do not click. Do not approve anything in MitID. Hang up and verify independently.
What has happened?
On 5 October 2026, the Danish authorities announced unauthorised access to CPR information, including names, addresses and CPR numbers relating to approximately 8.8 million registered people. This includes living people, people who have left Denmark and deceased people. The investigation is ongoing.
If you are an international employee or expat, CPR is Denmark’s personal identification number. You use it in many everyday dealings with authorities and services. Treat it carefully, but never use someone’s knowledge of it as proof of their identity.
Exposed personal details may make targeted scams more convincing. A CPR number alone is not the same as access to your MitID or bank account. The risk is that someone uses those details to gain your trust and persuade you to reveal more information or approve a payment.
Correct personal details can make a false call convincing
Relocare has always advised international employees to be cautious about unexpected requests for CPR or MitID information. The key message now needs to be even clearer: a caller may already have your correct details.
For example, someone could claim to represent the Danish Police, Skattestyrelsen (the Danish Tax Agency) or your bank. They might quote your CPR number and address, then say that you must pay an outstanding fine immediately through a link. This is an illustrative scam scenario, not a confirmed consequence of this particular incident.
Your phone may even display the real organisation’s number. As the Danish Police explain, criminals can manipulate caller ID, a technique called spoofing. The number on your screen is not proof of who is calling.
1. STOP: pause before taking action
- Do not provide passwords, MitID codes, one-time codes or payment-card details in response to an unexpected request.
- Do not approve a MitID request you did not initiate yourself. MitID is Denmark’s digital identity used for secure logins and approvals.
- Do not transfer money to a “safe account”, pay through an unexpected link or install software at a caller’s request.
- Urgency, threats and demands for secrecy are reasons to pause and verify.
2. DISCONNECT: end the conversation
You do not need to argue or establish whether the caller is lying. End the call. Avoid replying to a suspicious message or using its links. A simple response is: “I will contact the organisation myself through its official channels.”
3. VERIFY: contact the organisation independently
Find its contact details yourself on its official website. Do not use a phone number or link supplied by the caller, and do not rely on your call history.
- Police: use politi.dk. For non-emergency enquiries in Denmark, call 114.
- Danish Tax Agency: open skat.dk yourself and use its contact information or your secure tax account.
- Your bank: use your usual banking app or independently verified contact details.
- Public-authority messages: open Digital Post yourself through borger.dk or your usual trusted app. Digital Post is the secure mailbox used by Danish public authorities. Check any relevant message there and contact the authority if uncertain.
An empty mailbox does not by itself prove a call is false. The goal is to verify the specific request through a channel you have opened independently.
Consider adding a credit warning
A credit warning (kreditadvarsel) is a flag in the CPR system that warns lenders and businesses to take extra care before granting credit in your name. It can help reduce identity-fraud risk, but is not a guarantee against misuse and may complicate your own credit applications. Follow the official guidance to add or remove it.
If you have already shared details or paid
Contact your bank immediately if money or card details are involved. If your MitID may have been compromised, seek help promptly and block it where necessary through mitid.dk. Report suspected fraud or identity misuse to the police and keep relevant messages and transaction information.
The official Cyberhotline for digital security can guide you on the next steps: +45 33 37 00 37. You do not need to be certain that fraud has occurred before seeking advice.
A simple rule to remember
Knowing who you are does not prove who they are.
Share this reminder with your family and colleagues, especially people who are still learning how Danish authorities communicate. Familiar names and fluent Danish or English are not substitutes for independent verification.
Your CPR number is an identifier – it is not a password. STOP – DISCONNECT – VERIFY.