S 10,788,963 recordsThe membership management system of the Yakiniku King official app was accessed without authorization, and a leak was confirmed on October 3, 2026. Member numbers, names, email addresses and phone numbers were leaked for 10,788,963 of 10,808,784 registered users.
Unauthorized access & data leakConfirmedOfficial statement
S About 8,800,000 peopleA private Danish company's lawful access to search the CPR system was misused, and names, addresses and CPR numbers of about 8.8 million people were obtained without authorization. Irregular activity occurred during September 2026; the CPR administration became aware on October 2, learned the scope over the weekend, and the Ministry of Research, Higher Education and Digitalisation disclosed it on October 5. People registered with name and address protection are not affected. The company's access has been stopped, the police are investigating, and the case was reported to the Data Protection Agency (Datatilsynet).
Unauthorized access & data leakConfirmedOfficial statement
A About 220,000 recordsThe server of Scala Communications, the provider of an external service used for inquiry management, was accessed without authorization from October 2 to 3, 2026, and about 220,000 records, including names and account numbers of about 110,000 customers, may have leaked.
A 174,933 peopleThe official app's system was accessed without authorization, and the company announced it cannot rule out that names, phone numbers, addresses and other data of 174,933 users registered from November 2024 to September 15, 2026, including former members, leaked.
Unauthorized access & data leakPossibleOfficial statement
D 254 recordsIn the Amazon Pay donation flow, insufficient checking in the process that restores application data after authentication meant another user's name, address, phone number, email address and gift delivery information could be shown on a different user's screen. Between November 13, 2025 and September 7, 2026, 254 applications were affected; 19 of them reached the application screen and 6 proceeded to payment, all operated with the person's own Amazon account. No charges to other people's cards or Amazon accounts have been confirmed. The company says the fault was not in Amazon Pay's payment function.
Unauthorized access exploiting a vulnerability in Metabase, a tool used for internal data analysis, resulted in customer information such as email addresses and encrypted passwords being obtained for about 440,000 accounts, including those of former members.
Unauthorized access & data leakConfirmedOfficial statement
A vulnerability in the reservation site program was used as a foothold for unauthorized access to the core system, and data of about 1.05 million accounts, including names, addresses, email addresses and encrypted passwords, was taken out.
Unauthorized access & data leakConfirmedOfficial statement