On October 5, 2026, Denmark's Ministry of Research, Education and Digitalisation announced that unauthorized parties had accessed names, addresses, CPR numbers and related data for about 8.8 million of the roughly 11 million people in Det Centrale Personregister, the country's civil registration system. The ministry was careful about the mechanism. The register itself had not been hacked. Someone had misused a Danish company's lawful ability to search it, running a very large number of automated lookups during September 2026 until a CPR administration employee noticed irregular behavior on the evening of Friday, October 2. The company was small. The access lasted roughly ten days. Who did it, and how they obtained the company's access, remain unknown.
Denmark is not an outlier. It is the latest data point in a pattern that now spans at least three continents: national identity and civil registration systems whose central databases hold, but whose weak points sit at the edges, in the legitimate query channels that banks, telecoms, employers, and verification agents use every day. Nigeria's National Identity Management Commission suffered the same failure mode in 2024, when unauthorized websites used improperly governed API access to sell citizens' identity records for as little as ₦100 each. India's Aadhaar system has drawn years of documented legal and technical criticism over how its authorized-access ecosystem is governed. In each case the vault door held; the keys were the problem.
This article is about that structural weakness: what lawful third-party access frameworks actually do to national identity infrastructure, what the documented incidents show, and what a redesign that preserves legitimate use would need to change.
What a "Lawful Access Framework" Actually Is
Every large national identity system, whether Aadhaar in India, Nigeria's NIN database, Estonia's population register, GOV.UK One Login, or the US General Services Administration's Login.gov, rests on the same basic bargain. The state maintains an authoritative register of who people are. Outside parties, including banks complying with know-your-customer rules, telecoms registering SIM cards, employers verifying work authorization, and welfare agencies checking eligibility, need to confirm identity against that register. The state grants them a technical channel to do so.
The channels vary in mechanism but not in essence. Aadhaar exposes authentication and e-KYC interfaces that Authentication User Agencies and KYC User Agencies query, historically through direct API integration and, under its revised API framework, increasingly through OAuth-based flows in which the resident's consent is captured as a token governing the transaction. Estonia's X-Road data exchange layer brokers queries between government registries and authorized private entities. Nigeria's NIMC licenses verification agents and, until public exposure forced a reckoning, operated a NIN Verification Service through which those agents, and their subagents, could query the identity database. The eIDAS framework in the European Union and emerging digital identity wallets in the UK and US follow the same logic: a trusted intermediary presents an assertion, and the register, or a service in front of it, confirms it.
The design is not a mistake. Centralized verification is what allows a resident in rural Jharkhand to open a bank account with a twelve-digit number, allows a Nigerian bank to meet a Central Bank mandate to link accounts to Bank Verification Numbers, and allows Danish municipalities to deliver services without repeatedly re-establishing who someone is. The World Bank's Identification for Development (ID4D) initiative has documented how such systems expand access to services for the estimated hundreds of millions of people worldwide who lack legal identity. Any critique that ignores those gains is not serious.
But the same query channels that deliver those gains have a property that national data-protection law was largely not written to anticipate. Every identity check is a data extraction event. And across millions of checks by thousands of accessors, the aggregate of those events is a distributed copy of the population register that no single institution controls, that no regulator currently sees whole, and that no breach-notification regime was designed to govern.
The Nigeria Case: How a Verification Channel Became a Bazaar
The most complete public record of this failure mode comes from Nigeria, because investigative journalists documented it while it was running.
On March 16, 2024, the Foundation for Investigative Journalism reported that a private website, XpressVerify.com, was offering unrestricted lookups of Nigerians' National Identification Numbers, Bank Verification Numbers, phone numbers, and other personal details for trivial fees. The site was not a crude phishing front. It worked because NIMC had reopened a legitimate channel. The NIN Verification Service, first created in 2012, had been shut down in 2017 after a World Bank audit found that licensed agents could create their own application programming interfaces, enroll subagents without NIMC's knowledge, and charge them for the service without remitting anything to the commission. In February 2024, after a change in leadership, NIMC issued a circular restoring the NVS for use by verification agents. An NIMC staff member quoted by TheCable described the directive as reversing the security measures built into the system: "It is like opening the bank vault for the public to have a free run on the cash."

The scale was visible in the aftermarket. One unauthorized resale site, AnyVerify.com.ng, recorded an estimated 567,990 visits in February 2024 alone. In June 2024, NIMC publicly flagged five data-harvesting websites and denied that its database had been compromised. That denial was, in a narrow sense, accurate and, in the sense that matters, beside the point. Security analysts and the commission converged on the same conclusion: no one had hacked the core database. The leak ran through a channel NIMC itself had reopened and then failed to police, with some of its staff reportedly linked to profiting entities. The civil-society group Paradigm Initiative served pre-action legal notices on eight federal bodies in July 2024 demanding investigation and compensation.
Nigeria's episode is not primarily a story about a weak state. It is a story about a governance gap that any state running the same architecture could hit: a regulator that licenses accessors, delegates the technical details to those accessors, and then has no independent visibility into what they actually query.
The Denmark Case: The Same Vulnerability, Different Governance
What makes the October 2026 CPR incident instructive is how much Denmark got right, and what still slipped through.
The CPR system is one of the world's most mature civil registers, operating since 1968, underpinned by the CPR Act's Section 38 provisions that define what categories of private companies may look up. The Ministry of Research, Education and Digitalisation, under minister Christina Egelund, disclosed the incident within days of the administration noticing irregular behavior on October 2, and Datatilsynet, the Danish data protection authority, confirmed it had received the register's notification on Sunday, October 4 and had opened a review covering what happened, how it could happen, and who the data controller is. Officials confirmed that the names and addresses of people with name- and address-protection were not reached, though whether their CPR numbers were among the accessed data has not been established. Danish authorities stated that roughly 8.8 million of about 11 million registered persons had their data accessed, with the activity occurring during September 2026 and figures that the ministry says may be consolidated as the investigation continues.
But the incident also exposed open questions that lawful-access architectures generate everywhere. The notification Datatilsynet received described a very large number of automated lookups made to identify valid CPR numbers. Yet CPR's own published guidance states that CPR numbers are never disclosed to private parties, that the CPR number is normally the identifier a company submits rather than a field it receives back. No official source has yet publicly reconciled how CPR numbers came to be among the accessed data. The ministry has not named the company, has not said whether the channel was a bulk subscription arrangement under Section 38 or an electronic single-lookup route, and has not said how the unauthorized parties obtained the company's access. The minister has said authorities are not ruling out an international dimension.
Denmark's disclosure discipline is a model relative to most jurisdictions. The unresolved questions are the more general lesson: even in a system with a statutory access framework, a data protection authority with real powers, and rapid public notification, the operational reality of who holds what access, and through which specific technical route, remains opaque precisely at the moment the public needs to know it.
India: The Largest System Meets the Hardest Test

Aadhaar, the world's largest biometric identity system, has spent over a decade demonstrating both the value and the structural risk of authorized-access identity infrastructure.
The legal scholarship is blunt about the architecture's governance gaps. Writing in the National Law School of India Review, Vrinda Bhandari and Renuka Sane examined the Aadhaar Act, its ordinance, and its regulations from the perspective of accountability, delegation, and grievance redressal, and found that much was delegated to the Unique Identification Authority of India without adequate checks and balances, that UIDAI had further delegated the setting of several standards and procedures to its future self, which the authors said left the process operating in a legal vacuum, and that the accountability framework was weak and beset with conflict of interest because there were no statutorily mandated accountability standards. Their conclusion on grievance redressal and enforcement was similarly severe: the regulations in that area, they found, were also weak.
The technical literature corroborates the concern that the edge, not the center, is the soft surface. A 2024 survey by Debanjan Sadhya and Tanya Sahu in Computers & Security catalogued the security features of Aadhaar's demographic and biometric layers and investigated possible linkage attacks, a class of risks that arises because different government databases connect through the Aadhaar number, so that data assembled across those systems can reveal more about an individual than any single one was designed to show. A 2022 analysis from the IACR Cryptology ePrint Archive by Tiwari and colleagues described the first known cryptographic issue within the Aadhaar infrastructure, noted a workaround that prevented it from being exploitable at scale, and systematically rated the security and privacy limitations and threat actors across the system, including an examination of the legitimacy of alleged security breaches.
None of this means Aadhaar's central database has been cracked, and India's Supreme Court, in its 2018 judgment substantially upholding the Act's constitutionality, accepted the state's contention that the core biometric repository was adequately protected. What it means is that the system's attackable surface includes every authorized query route, every agency licensed to use it, and every downstream database that stores what those queries return.
The Core Problem: Query Trails Silently Build a Shadow Register
The deeper structural issue deserves a name of its own, because it is not an incident but a property of the architecture.
When a bank runs an e-KYC check, it receives a data packet: name, address, date of birth, photograph. When a telecom registers a SIM against Aadhaar, it receives a similar packet. When a Nigerian agent verifies a NIN, it receives a record. Each individual transaction may be lawful, consented, and logged. But the aggregate of millions of such transactions, held in the logs, staging tables, backups, and data warehouses of thousands of private intermediaries, is a partial copy of the national register, distributed across the economy, governed by the data-handling practices of each accessor rather than by the standards of the register itself.

Few data-protection laws were written with this emergent object in mind. The European Union's General Data Protection Regulation, the UK's Data Protection Act 2018, India's Digital Personal Data Protection Act 2023, and Nigeria's Data Protection Act 2023 all regulate the conduct of data controllers and processors. They impose duties of security, purpose limitation, and minimization on each accessor. But none of these statutes treats the accumulated query-trail across all accessors as a systemic asset, and none of these regulators is positioned to audit it in aggregate. The Estonian data protection regime, often cited as the gold standard, requires access logging to the population register and gives individuals the right to see who has queried their record, but even that right attaches to one register's logs at a time, not to the distributed whole.
This is the point at which the technical and the legal problems compound. If an attacker can extract the data from one careless intermediary, the integrity of the central register's controls is moot. The 2024 Nigerian episode is the demonstration case: the value of NIMC's central database security was set by the weakest licensed agent in the chain.
Where the Counter-Evidence Points
The response to all this cannot be to abolish identity verification infrastructure, because the benefits are real and measured.
The World Bank's ID4D program has documented how legal identity enables access to finance, health care, education, and social protection, particularly for women, refugees, and the rural poor, and has made the design principle 'privacy by design' an explicit element of its guidance on identification systems. India's own experience includes measured results on both sides of the ledger: studies of Aadhaar's effect on public distribution and subsidy systems, including work by economists such as Jean Drèze and Reetika Khera published in the Economic & Political Weekly, weigh the claimed efficiency gains from de-duplication against documented exclusion costs in some implementations, a record that cuts against both naive boosterism and naive abolitionism. Denmark's CPR register underpins one of the most trusted digital government ecosystems in the world.

So the counter-evidence to any simplistic security narrative is that these systems demonstrably deliver inclusion and efficiency at population scale, and that the question is not whether to have them but how to govern the access surface they necessarily create. That framing also disciplines the threat model. The Danish incident was caught in days by an alert employee. The Nigerian system ran for months. The difference was not cryptographic; it was audit capacity and institutional willingness to notice.
How to Redesign Access Without Breaking Its Use
The technical and legal literature points to a consistent set of design changes, each aimed at the same target: reducing what each authorized query reveals, and increasing the independent visibility of what every accessor does.
Tighten the technical channel first. The most direct structural fix is to stop returning identity data at all where a simple assertion will do. Instead of a bank receiving a name, address, and date of birth, it receives a cryptographic proof that the credential holder satisfies a property: is over eighteen, is a resident, is entitled to open an account. The W3C's Verifiable Credentials Data Model, the OpenID Foundation's work on selective disclosure and SIOP-style flows, and the ISO/IEC JTC1 SC 27 standards work on privacy-enhancing identity management all point in this direction. A concrete early public-sector example is the City of Buenos Aires, which in October 2024 rolled out a zero-knowledge-based decentralized identity layer, QuarkID, on its miBA platform for roughly 3.6 million residents, allowing residents to prove attributes, such as age, without revealing the underlying document. Whether such systems scale to a billion users with Aadhaar's reliability profile is an open engineering question, and the honest formulation is that selective disclosure reduces the per-query leakage surface rather than eliminating the need for trusted verification.
Make accreditation independent and adversarial. The Bhandari–Sane critique of UIDAI's self-delegation generalizes: an identity authority should not be the sole judge of its own access-control standards. Independent accreditation of verifiers, on the model that eIDAS uses for trust service providers, with published criteria and revocable status, creates a supervisory relationship that a self-regulated authority cannot provide.
Treat audit logs as critical infrastructure. The notification Datatilsynet received, describing "a very large number of automated lookups," shows the detection value of log analysis, and the Nigerian case shows what happens without it. Logs at both the register and the accessor should be tamper-evident, retained long enough to support longitudinal forensics, and reviewable by an authority that does not answer to the operator. Estonia's per-individual access log, which any resident can inspect, is the strongest citizen-facing model currently deployed, and it directly addresses the insider-threat surface by making every query attributable.
Fix liability allocation. The current default in most jurisdictions is that a person harmed by leakage through a licensed accessor faces a chain of intermediaries, each pointing at the other. The 2024 Nigerian response, an NDPC investigation plus pre-action notices from civil society rather than an effective private remedy for affected citizens, shows the gap. A liability regime that places primary responsibility on the licensed accessor for misuse of its channel, with statutory redress for individuals, aligns incentives correctly: it makes each accessor treat its query credentials and logs as the high-value assets they are.
Build regulator and audit capacity deliberately. Supreme audit institutions, the US GAO, the UK National Audit Office, India's CAG, Estonia's National Audit Office, have the mandate to examine whether public bodies deliver value and protect the data entrusted to them. Several, including the UK's NAO in its reports on digital identity assurance, and the GAO in its work on federal identity programs including Login.gov, have already flagged governance and assurance questions. A standing audit function for the third-party access ecosystem, with access to both the register's logs and the accessors', is the institutional fix that does not depend on any new technology.
Let watchdogs check the work. The Nigeria episode was broken by investigative journalism, not by the commission's own supervision. Access Now, Privacy International, Paradigm Initiative, IT for Change, and the Electronic Frontier Foundation have each documented access-governance failures in national identity systems. Their role is not decorative. A regulator that knows that external researchers can independently test the openness of a verification channel, through legitimate means and within legal bounds, has a stronger incentive to maintain the controls that prevent the next XpressVerify.
What the Evidence Shows

The documented record, from Denmark in October 2026 back to the structural critiques of Aadhaar's enabling law, supports a conclusion that is neither that national identity infrastructure is inherently unsafe nor that its access channels are adequately governed today.
What the record shows is specific. Centralized databases with strong protections at the core are being exploited through their lawful periphery, by actors who never need to breach anything, because the periphery is where the data actually moves. The Nigerian case, the Danish case, and the Indian legal and technical literature are three different lenses on the same structural fact, established by investigative reporting, official disclosure, and legal and technical scholarship respectively. The mitigation direction that emerges from the standards bodies, regulators, and civil-society responses surveyed above is consistent: minimize what each query reveals, make every query attributable and auditable by someone independent of the operator, and put the cost of misuse on the party that controls the channel.
The unresolved questions are equally specific. How Danish CPR numbers came to be among the accessed data when the channel officially never discloses them to private parties. Whether India's Digital Personal Data Protection Act 2023, and the regulatory capacity it presumes, will close the accountability gap Aadhaar's own legal architecture created. Whether Nigeria's NDPC can enforce against an ecosystem where the commission's own staff were reportedly implicated. Those gaps should temper any confident claim that a particular redesign solves the problem, because the evidence so far suggests the vulnerability surface shrinks with governance capacity rather than with technology alone.
The honest bottom line is that the question is no longer whether lawful access frameworks can expose a nation's population data without breaching anything. Nigeria and Denmark have answered that with incidents; India has answered it with years of documented legal and technical critique. The question is whether the institutions that license the access will acquire, before the next incident, the visibility and accountability to match the power that access confers.
Sources / References
- Bhandari, Vrinda, and Renuka Sane. "A Critique of Aadhaar Framework." National Law School of India Review 31, no. 1 (2019). https://repository.nls.ac.in/cgi/viewcontent.cgi?article=1257&context=nlsir
- Sadhya, Debanjan, and Tanya Sahu. "A critical survey of the security and privacy aspects of the Aadhaar framework." Computers & Security 140 (May 2024): 103782. https://www.sciencedirect.com/science/article/abs/pii/S016740482400083X
- Tiwari, Pratyush Ranjan, Dhruv Agarwal, Prakhar Jain, Swagam Dasgupta, Preetha Datta, Vineet Reddy, and Debayan Gupta. "India's 'Aadhaar' Biometric ID: Structure, Security, and Vulnerabilities." IACR Cryptology ePrint Archive, Paper 2022/481 (2022). https://eprint.iacr.org/2022/481
- Ojukwu, Daniel. "EXPOSED: How NIMC Leaked Nigerians' Data to Fraudulent Verification Agents." Foundation for Investigative Journalism, March 19, 2024. https://fij.ng/article/exposed-how-nimc-leaked-nigerians-data-to-fraudulent-verification-agents/
- "National Identity Management Commission 2024 data breach." Cyber Breaches Monitor. https://www.cyberbreaches.org/en/incidents/nimc-nin-exposure-2024
- "Denmark CPR Registry: Lawful Third-Party Lookup Access Abused." Rescana, October 6, 2026. https://www.rescana.com/post/denmark-cpr-registry-third-party-access-abuse-8-8m-records
- "Buenos Aires Sets Global Precedent by Empowering 3.6 Million Citizens with Blockchain-based Digital Identity on miBA platform." GlobeNewswire, October 22, 2024. https://www.globenewswire.com/news-release/2024/10/22/2967256/0/en/Buenos-Aires-Sets-Global-Precedent-by-Empowering-3-6-Million-Citizens-with-Blockchain-based-Digital-Identity-on-miBA-platform.html
- "Aadhaar in numbers." Unique Identification Authority of India. https://uidai.gov.in/
- Khera, Reetika. "Impact of Aadhaar on Welfare Programs." Economic & Political Weekly 52, no. 50 (2017): 61–70.
- Drèze, Jean, et al. "Aadhaar and Food Security in Jharkhand: Pain Without Gain?" Economic & Political Weekly 52, no. 50 (2017): 50–59.
- "Identification for Development (ID4D) Initiative." World Bank Group. https://id4d.worldbank.org/
Comments (5)
Continue exploring
The Kidnappers Outsmart Nigeria’s Surveillance State
Nigeria has more tools to track kidnappers than ever, but fragmented data systems and slow institutional response leave criminal…
The Army Is Turning Military Land Into an AI Compute Platform
Carlyle and CyrusOne won exclusive negotiations to build commercial hyperscale data centers on roughly 2,600 acres of Army land…
Russia's Dawei Bet: A Megaport on the Front Line of Myanmar's Civil War
Russia is backing a deep-sea port on Myanmar's Andaman coast while the army burns villages to clear the land around it, a sign…
I have been following the EU Digital Identity Wallet rollout, and the article's mention of Aadhaar's shift toward OAuth-based consent tokens makes me wonder whether that same architectural move could actually prevent another Nigeria or Denmark situation in Europe.
The line "the vault door held; the keys were the problem" is an uncomfortably accurate summary of both the Denmark and Nigeria cases.
What ended up happening to that small Danish company after October 2 — is there any indication its credentials were stolen through phishing or did someone with insider involvement hand them over?
I'm not fully convinced the cross-country comparison holds, because Nigeria's licensed-agent ecosystem and Denmark's single misused corporate channel look structurally different enough that lumping them together as one failure mode may obscure more than it reveals.
I would love a follow-up that actually walks through what the "redesign that preserves legitimate use" would require in practice, since the article gestures at consent tokens and tighter access governance without specifying how audit signals across millions of daily lookups by thousands of accessors would ever be aggregated and reviewed. The Denmark case makes that gap feel concrete: a single employee noticed irregular behavior on a Friday evening, which is a remarkably thin safety net for a system that holds nearly an entire national population. Is there a working model, perhaps in Estonia's X-Road logs or in the revised Aadhaar API framework, that demonstrates real-time anomaly detection on authorized query streams at scale? And if not, which body should actually be setting that baseline, ID4D or a national regulator?