Home › Technology › `123456' password used in Danish CPR data breach
Technology

`123456' password used in Danish CPR data breach

Key Points

At least three accounts at the company linked to a major breach of Denmark’s CPR register reportedly used the password “123456”, including an administrator account. At least three user accounts at the Funen-based IT company Pays used the password “123456” when hackers gained access to Denmark’s CPR register, Politiken reports. One of them was the company’s administrator account.

At least three accounts at the company linked to a major breach of Denmark’s CPR register reportedly used the password “123456”, including an administrator account. At least three user accounts at the Funen-based IT company Pays used the password “123456” when hackers gained access to Denmark’s CPR register, Politiken reports. One of them was the company’s administrator account. The breach exposed information linked to around 8.8 million CPR numbers. The CPR system is Denmark’s central civil registration database and contains personal information on people living or previously registered in Denmark. The newspaper Politiken reviewed data from the breach that the hacker allegedly used to gain access to the system. Jens Myrup Pedersen, professor at Aarhus University’s Department of Electrical and Computer Engineering, described the company’s password security as “hopeless”. “There is really no security, it is an open door. A password like ‘123456’ is one of the very first things you would guess if you took a list of common passwords,” he told Politiken. “I find it hard to see that you could have worse security. It was a matter of time before things went wrong.” Pays ApS, based in Odense, confirmed to TV 2 on Friday that it was the company whose access had been compromised. “We can confirm that we are the company that has been subjected to an attack where our legal access to search for information in the CPR system has been abused,” managing director and owner Sophie Laursen said in an email to TV 2. The hacker had access to the CPR register from 10 September for a total of 21 days and 17 hours. An anonymous hacker told Politiken on Thursday that they were behind the attack and claimed gaining access had not been particularly difficult. According to the hacker, access was initially obtained using a leaked password belonging to a former employee of a small Danish company. The hacker then allegedly created two computer programs to retrieve information from the CPR system and store it externally. The hacker told Politiken that there were no plans to sell or publish the information. Private companies and associations can be granted access to information in Denmark’s CPR register when they have a legitimate need, for example to obtain address information about customers or members. According to Denmark’s Central Business Register, Pays ApS had two employees as of July 2026.
Danish CPR (ORG) Denmark (LOCATION) CPR register (ORG) Funen (ORG) Politiken (PERSON) Jens Myrup Pedersen (PERSON) Aarhus University’s (ORG) Department of Electrical and Computer Engineering (ORG) Pays ApS (ORG) Odense (LOCATION) CPR (ORG) Sophie Laursen (PERSON) TV 2 (ORG) Danish (ORG) Central Business Register (ORG)
Originally published by Hacker News Read original →