# TRACE CPR 2026: public findings Snapshot date: 5 October 2026 Case status: OPEN ## 1. Confirmed public record CPR says unauthorized parties used a private Danish company’s lawful CPR access and obtained names, addresses, CPR numbers and other information concerning about 8.8 million registered persons. Datatilsynet says the activity involved a very large number of automated lookups aimed at identifying valid CPR numbers. The minister told Ritzau the misuse ran for around ten days in September and said the security around this access was not good enough and should have triggered warnings earlier. Publicly undisclosed on this snapshot: company name, CPR product, credential type, compromise mechanism, exact request count, peak rate, normal customer baseline, alert thresholds, full affected-person mapping and data destination after retrieval. ## 2. Scale scenario A conservative scenario of 8.8 million returned persons across ten days equals 880,000 persons per day, 36,667 per hour, 611 per minute and about 10.2 per second. This is not a claim about the actual request rate. One request may return zero, one or multiple persons. Failed enumeration attempts would raise the real request count. ## 3. Public CPR surface preserved on 5 October The collector ran from 19:57:05 to 20:02:56 CEST. It captured 200 pages, observed 205 unique URLs and fetched 17 referenced resources. Scope was public and low impact. No login, form submission, endpoint guessing, CPR enumeration, exploitation, authentication bypass or port scan was performed. Observed in the capture: - HSTS was present on all 200 responses. - CSP and CSP Report Only were absent on all 180 HTML responses in the HTML subset. - Both standard security.txt locations returned HTTP 404. - DMARC requested reject. - The public password page sent CPR Direkte and CPR Udtræk FTP one-time-password changes to a web-preprod.cpr.dk URL. - The same public page stated that CPR Direkte passwords must be exactly 8 characters. The last two points raise operational hardening and environment-boundary questions. They do not establish the September breach vector. ## 4. Questions that require records The public record should identify the company and CPR product, describe the credential path, publish request telemetry and alert history, explain rate limits and enumeration controls, map the affected population, explain the notification basis under GDPR Article 34 and disclose the dated control changes made after the incident. ## 5. Integrity rule SHA-256 verifies file identity. It does not prove causation. Each claim stands or falls on the underlying source and its stated limit.