People can be told to watch for fraud, but that does not answer how the access ran for days, what product was used, what the monitoring saw, who was affected or what changed before access was restored. Those answers should exist in logs, contracts, configuration, incident tickets and formal risk records.
Which private company's access was abused?
Which CPR product and interface were used during the unauthorized activity?
Which credential or identity was used, and how was it obtained or misused?
What was the exact start timestamp, end timestamp and first anomalous event?
How many requests were made in total, including unsuccessful lookups?
How many unique person records were returned, and which fields were returned for each product path?
What were the normal request baseline, peak rate and deviation for this customer before the incident?
Which rate limits, quotas, enumeration controls and automated suspension rules existed on that access path?
Which alerts fired before 2 October, if any, and who received them?
Why did the activity require a human employee to notice it after around ten days?
Can each affected person obtain a record showing whether their CPR number was queried during the incident?
Were CPR numbers belonging to people with name and address protection accessed even though their names and addresses were excluded?
What legal and risk assessment supports the chosen method of notifying affected people under GDPR Article 34?
What prior Datatilsynet inspections, audits or supervisory actions covered private-company CPR access, automated high-volume lookups, anomaly detection or the audit trails described in CPR’s own terms?
What concrete controls were changed, tested and approved before private-company CPR access was restored at 11:57 on 5 October?