TL;DR
Get privacy and security gear delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
Politiken reports that at least three accounts at Pays ApS, including an administrator account, used the password “123456” when the company’s authorized access to Denmark’s CPR register was abused. The breach involved information linked to about 8.8 million CPR numbers; the exact data retrieved and the identities of affected people have not been detailed in the supplied reporting.
At least three accounts at Pays ApS, including an administrator account, reportedly used the password “123456” when the company’s access to Denmark’s central civil register was abused, according to Politiken. The breach involved information linked to about 8.8 million CPR numbers, though the precise records accessed have not been specified in the reporting provided; see the Denmark data breach report.
Politiken reported that it reviewed data allegedly used by the hacker to gain access to the CPR system and found that at least three Pays user accounts had the same widely used password. The report identified one of them as an administrator account. Pays, an IT company based in Odense, confirmed to TV 2 that it was the company whose authorized access had been compromised.
Pays managing director and owner Sophie Laursen said the company’s legal access to search the register had been abused in an attack. The reported access began on September 10 and lasted 21 days and 17 hours. The source material does not state when the intrusion was detected or when access was shut down.
An anonymous person who told Politiken they carried out the attack claimed they first used a leaked password belonging to a former employee of a small Danish company. The person also said they created two programs to retrieve register information and store it elsewhere. These details are the hacker’s account of events, not independently established findings in the material provided.
Exposure Across Denmark’s Civil Register
The CPR register is Denmark’s central civil registration database, holding personal information about people who live in or have previously been registered in the country. Information associated with around 8.8 million CPR numbers was involved in the breach, a scale that makes the incident relevant well beyond Pays and its customers.
The report does not establish that every person linked to those numbers had information retrieved, or that every type of personal data in the register was exposed. Still, misuse of a company’s authorized connection to a government register raises questions about how access credentials are protected, monitored and limited. If information was copied outside the system, it could also be difficult to determine whether it has been deleted or shared.
Jens Myrup Pedersen, a professor in Aarhus University’s Department of Electrical and Computer Engineering, criticized the reported password practices. His comments are an expert assessment of the password security described by Politiken; they do not by themselves establish the full technical cause or scope of the breach.
password manager for secure password storage
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How Pays Could Search the Register
Denmark allows some private companies and associations to access CPR information when they have a legitimate need. One example is obtaining address information about customers or members. Pays had such legal search access, according to Laursen’s statement to TV 2; the company said that this access was abused in the attack.
The distinction between authorized access and its alleged misuse matters: the reporting describes an attacker gaining entry through credentials and then using the connection to the register, rather than claiming that the CPR system itself was publicly accessible. Denmark’s Central Business Register listed Pays as having two employees in July 2026. That figure provides company-size context but does not establish how its systems were managed or who had access to the accounts.
““There is really no security, it is an open door. A password like ‘123456’ is one of the very first things you would guess if you took a list of common passwords.””
— Jens Myrup Pedersen, professor at Aarhus University, speaking to Politiken
multi-factor authentication device
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Scope and Data Use Still Unclear
The reporting does not say precisely which records were retrieved, how many individuals’ information was copied, or whether sensitive details beyond information linked to CPR numbers were involved. It also does not describe the contents of the data reviewed by Politiken in enough detail to determine the full exposure.
The anonymous hacker told Politiken there were no plans to sell or publish the information. That assurance comes from the person claiming responsibility and does not confirm that the information remains private, has been deleted, or has not been passed to anyone else. The supplied reports also do not include findings from law enforcement, a regulator or an independent technical investigation about the attack’s route, the accounts involved, or any steps taken to secure them.
As an affiliate, we earn on qualifying purchases.
Investigation and Access Controls
The next developments to watch are any findings from authorities or technical investigators on how the credentials were obtained, what information was queried or copied, and whether it has been contained. Further detail from Pays or the public bodies responsible for CPR access could clarify whether the reported passwords were active during the intrusion and what safeguards have since changed.
The supplied reporting does not announce a timetable for an investigation, a notification process for people whose information may be affected, or changes to Pays’ access. Until those details are provided, the confirmed position is that Pays acknowledged an attack abusing its register access, while the account of the attacker’s methods and the precise consequences remain incomplete.
As an affiliate, we earn on qualifying purchases.
Key Questions
What happened in the Danish CPR breach?
Pays ApS confirmed that an attack abused its authorized access to search Denmark’s CPR register. Politiken reported that at least three company accounts, including an administrator account, used the password “123456”.
How many CPR numbers were involved?
The breach was reported to involve information linked to about 8.8 million CPR numbers. The available reporting does not say how many individual records were actually retrieved.
When did the reported access take place?
The reported access began on September 10 and lasted 21 days and 17 hours. The supplied material does not specify when the intrusion was discovered or stopped.
Was the stolen information published or sold?
An anonymous person claiming responsibility told Politiken there were no plans to sell or publish the information. That statement has not established whether data was copied, shared, deleted or otherwise used.
What remains unknown about the incident?
The exact records accessed, the number of people affected, the full method of entry and the results of any official investigation have not been detailed in the supplied reporting.
Source: hn
Halloween Picks
halloween
As an affiliate, we earn on qualifying purchases.
