{
  "case_id": "TRACE-CPR-2026-10-05",
  "title": "CPR national identity infrastructure security incident",
  "status": "open",
  "snapshot_date": "2026-10-05",
  "editorial_rule": "Claim -> evidence -> consequence -> limit",
  "official_record": [
    {
      "id": "OFF-001",
      "claim": "CPR says unauthorized parties used a private Danish company's lawful access and obtained names, addresses, CPR numbers and other information concerning about 8.8 million registered persons.",
      "source": "https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger",
      "limit": "The public announcement does not identify the company or disclose the complete person-by-person affected set."
    },
    {
      "id": "OFF-002",
      "claim": "The ministry says CPR noticed irregular behavior on the evening of 2 October 2026 and the scale became clear during the weekend.",
      "source": "https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/",
      "limit": "This is the public timeline available on 5 October, not a forensic reconstruction of every alert or request."
    },
    {
      "id": "OFF-003",
      "claim": "Datatilsynet says the notification describes a very large number of automated lookups intended to identify valid CPR numbers and says it received the notification on 4 October.",
      "source": "https://www.datatilsynet.dk/presse-og-nyheder/nyhedsarkiv/2026/okt/datatilsynet-er-opmaerksom-paa-sag-om-opslag-i-cpr",
      "limit": "Datatilsynet says the case is under investigation and responsibility is still being established."
    },
    {
      "id": "OFF-004",
      "claim": "The minister told Ritzau the misuse continued for around ten days in September and acknowledged that security around this access was not good enough and should have triggered warnings earlier.",
      "source": "https://www.dknyt.dk/ritzau/47196484-71a7-4e4e-83ad-7de84952f9be",
      "limit": "This record relies on the minister statement as reported by Ritzau."
    },
    {
      "id": "OFF-005",
      "claim": "The ministry warns citizens to remain cautious even when an incoming contact appears to know their name, address and CPR number.",
      "source": "https://ufm.dk/aktuelt/pressemeddelelser/2026/oktober/omfattende-uautoriseret-adgang-til-borgeres-cpr-oplysninger/",
      "limit": "This establishes an official warning about fraud risk. It does not establish that every affected person will be targeted."
    },
    {
      "id": "OFF-006",
      "claim": "CPR published on 5 October that private companies’ access to CPR had been restored at 11:57.",
      "source": "https://www.cpr.dk/cpr-nyt/nyhedsarkiv/2026/okt/private-virksomheder",
      "limit": "The public page title establishes restoration time. This snapshot does not claim which technical controls were changed before restoration unless separately documented."
    },
    {
      "id": "OFF-007",
      "claim": "Later on 5 October, the minister said it was too early to say whether some citizens might need new CPR numbers after the leak.",
      "source": "https://ni.dk/ni-news/id/3923f00a-ff90-4651-933f-d39ec826229c/Minister-efter-orientering--Udelukker-ikke-nye-CPR-numre-efter-l%C3%A6k",
      "limit": "This is secondary reporting of a minister statement. No decision to replace CPR numbers is recorded here."
    },
    {
      "id": "OFF-008",
      "claim": "Herning Municipality says CPR number must temporarily not be used as the sole basis for identifying a citizen and tightened identity checks after the national CPR leak.",
      "source": "https://www.herning.dk/nyheder/2026/skaerpet-opmaerksomhed-ved-identifikation-af-borgere",
      "limit": "This documents one municipality’s operational response. It is not presented as a nationwide rule."
    }
  ],
  "scale_scenario": {
    "input_person_records": 8800000,
    "assumed_days": 10,
    "persons_per_day": 880000,
    "persons_per_hour": 36666.6667,
    "persons_per_minute": 611.1111,
    "persons_per_second": 10.1852,
    "limit": "Scenario floor only. One request may return zero, one or multiple persons depending on product and query semantics. Failed enumeration attempts would increase the real request count."
  },
  "open_questions": [
    "company identity",
    "CPR product/interface",
    "credential type",
    "credential compromise or misuse mechanism",
    "exact request count",
    "peak request rate",
    "customer baseline",
    "rate limits and quotas",
    "enumeration detection controls",
    "automated suspension rules",
    "alerts before 2 October",
    "full affected-person mapping",
    "notification basis under GDPR Article 34",
    "post-incident control changes",
    "which contractual audit trail applies to the breached product",
    "whether required monthly or quarterly security reviews detected anomalies",
    "whether billing or transaction counters diverged from customer baseline",
    "whether any system-to-system online-batch approval existed for the observed activity",
    "what concrete controls changed before private-company CPR access was restored at 11:57 on 5 October",
    "whether an incident-specific person-by-person affected-record lookup will be provided",
    "which exact fields were returned for each affected person",
    "which public and private identity-verification procedures have been changed because name, address and CPR number can no longer be treated as sufficient proof of identity"
  ],
  "integrity_note": "SHA-256 proves file identity, not causation. Every finding must remain attached to its source and stated limit.",
  "control_record": {
    "source_file": "control-record.json",
    "core_point": "CPR standard terms describe product-dependent audit trails: per-query logs for CPRWeb; monthly transaction statistics and security-officer review for system-to-system access; and Datafordeler Logpoint records plus recurring controls.",
    "limit": "The incident product remains undisclosed. The existence of a documented control does not prove that it operated correctly during the incident."
  },
  "editorial_scope_note": "Official sources confirm names, addresses, CPR numbers and other information. This snapshot does not infer that every category stored in CPR was obtained.",
  "control_context": [
    {
      "id": "CTX-001",
      "claim": "CPR documentation recommends a match analysis on up to 5,000 of a company’s people before matching a large population using Adressematch.",
      "source": "https://www.cpr.dk/kunder/private-virksomheder/adressematch-udtraek/match-analyse",
      "limit": "This documents an authorized large-population workflow. It does not identify the product used in the September incident."
    }
  ],
  "public_release_policy": {
    "version": "V5",
    "rule": "Publish accountability evidence needed to test the incident narrative; withhold operational hardening inventories and unrelated attack-relevant detail while the breach path remains unconfirmed.",
    "excluded_from_public_package": [
      "full crawl index",
      "security-header matrix",
      "error-path inventory",
      "cookie/header inventories",
      "preproduction/password workflow details",
      "raw collector artifact list"
    ],
    "reason": "Those details are not established as the September breach path and are not needed to support the core accountability claims."
  },
  "supervision_questions": [
    "Which prior Datatilsynet inspections or supervisory actions covered private-company CPR access?",
    "Did prior supervision test automated high-volume lookups, anomaly detection, access review or the relevant audit trail?",
    "What findings, orders, sanctions or remediation follow from the current investigation?"
  ],
  "people_burden_note": "Closing an access route does not retrieve copies already obtained. Downstream burden can include stronger identity verification, fraud monitoring/reporting and time spent on remediation; this note does not claim every affected person will experience each consequence.",
  "supervision_note": "CPR is operated through the CPR administration. Datatilsynet is the independent supervisory authority. The public record reviewed here does not establish what prior supervisory testing covered private-company CPR access or automated high-volume lookup controls."
}