# Danish CPR Breach Exposes Supplier Risks

Unauthorized users exploited a private company’s legitimate access to Denmark’s Central Register of Persons (CPR), exposing names, addresses, and CPR numbers associated with approximately 8.8 million registered people. The incident demonstrates how supplier access can create exposure beyond an agency’s own systems. The report identifies no specific procurement, contract, or solicitation.

- Procurement teams can use the incident to assess how supplier access is granted and limited, including whether each supplier and user has only the access needed for their work.
- Organizations may benefit from continuous supplier monitoring and detection of unusual activity or data loss, rather than relying solely on periodic reviews.
- Contractors handling sensitive government data should evaluate how their access controls and monitoring address the risk of compromised accounts using legitimate connections.

**Jurisdictions:** international
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 07, 2026

### Government Entities
- Danish government
- Ministry of Research, Education and Digitalisation

### Key Quotes
> A compromised account at a single supplier can bypass an organization's core security controls and turn a legitimate connection into a massive data exposure.
> — Dray Agha, Senior Manager of Security Operations at Huntress

> Vendor risk management cannot rely on static, annual reviews.
> — Michael Centrella, Head of Public Policy at SecurityScorecard

> Organizations must collect and retain only what they need, restrict access to what each user or supplier requires, and monitor for unusual activity.
> — Jamie Akhtar, CEO of CyberSmart

### Sources
- [
	Danish CPR Breach Highlights Challenge of Supply Chain Risk - Infosecurity Magazine
](https://www.infosecurity-magazine.com/news/danish-cpr-breach-supply-chain-risk) - Infosecurity Magazine